Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9108

Опубликовано: 14 июл. 2026
Источник: nvd
EPSS Низкий

Описание

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.

EPSS

Процентиль: 1%
0.00109
Низкий

Дефекты

CWE-22

Связанные уязвимости

github
17 дней назад

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.

CVSS3: 6.7
fstec
18 дней назад

Уязвимость интегрированной среды проектирования Studio 5000 Logix Designer, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю получить несанкционированный доступ на создание файлов и выполнить произвольный код

EPSS

Процентиль: 1%
0.00109
Низкий

Дефекты

CWE-22