Логотип exploitDog
bind:CVE-2021-27471
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-27471

Количество 3

Количество 3

nvd логотип

CVE-2021-27471

почти 4 года назад

The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. User interaction is required for this exploit to be successful.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-qj5f-6rc3-vgfv

почти 4 года назад

The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. User interaction is required for this exploit to be successful.

CVSS3: 8.6
EPSS: Низкий
fstec логотип

BDU:2022-05265

больше 4 лет назад

Уязвимость программного обеспечения проектирования и настройки контроллеров Connected Components Workbench (CCW), связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-27471

The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. User interaction is required for this exploit to be successful.

CVSS3: 7.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-qj5f-6rc3-vgfv

The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. User interaction is required for this exploit to be successful.

CVSS3: 8.6
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2022-05265

Уязвимость программного обеспечения проектирования и настройки контроллеров Connected Components Workbench (CCW), связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.7
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу