Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9127

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
Версия до 32.04 (включая)
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
Версия от 33.00 (включая) до 33.02 (исключая)
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
Версия от 34.00 (включая) до 34.02 (исключая)
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:35.00:*:*:*:*:*:*:*

EPSS

Процентиль: 1%
0.00109
Низкий

7.5 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
github
2 месяца назад

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость интегрированной среды проектирования Studio 5000 Logix Designer, связанная с недостатками процедуры авторизации, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 1%
0.00109
Низкий

7.5 High

CVSS3

Дефекты

CWE-863