CVE-2021-22665

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
18/03/2021
Last modified:
25/03/2021

Description

Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and complete control of the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:drivetools_add-on_profiles:*:*:*:*:*:*:*:* 4.12 (including)
cpe:2.3:a:rockwellautomation:drivetools_sp:*:*:*:*:*:*:*:* 5.13 (including)