CVE-2022-2463

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
25/08/2022
Last modified:
27/08/2022

Description

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running at the SYSTEM level, then the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:isagraf_workbench:*:*:*:*:*:*:*:* 6.0 (including) 6.6.9 (including)


References to Advisories, Solutions, and Tools