Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9128

Опубликовано: 14 июл. 2026
Источник: nvd
EPSS Низкий

Описание

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.

EPSS

Процентиль: 1%
0.00096
Низкий

Дефекты

CWE-428

Связанные уязвимости

github
17 дней назад

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.

CVSS3: 7.5
fstec
18 дней назад

Уязвимость модуля External Tools (Внешние инструменты) интегрированной среды проектирования Studio 5000 Logix Designer, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 1%
0.00096
Низкий

Дефекты

CWE-428