CVE-2018-10619

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
07/06/2018
Last modified:
09/10/2019

Description

An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:rslinx_classic:*:*:*:*:*:*:*:* 3.90.01 (excluding)
cpe:2.3:a:rockwellautomation:factorytalk_linx_gateway:*:*:*:*:*:*:*:* 3.90.00 (excluding)