← Back

CVE-2022-2463

nvd nist
Published: Aug 25, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running at the SYSTEM level, then the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.

Affected (1)

Isagraf Workbench
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 6.0 to 6.6.9

References (2)

Source: ics-cert@hq.dhs.gov
MitigationPatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchThird Party AdvisoryUS Government Resource

Timeline

No history available yet.