PT-2021-6880 · Unknown · Isagraf Workbench+2
Kimiya
·
Published
2021-10-21
·
Updated
2022-05-26
·
CVE-2022-1118
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Connected Components Workbench versions 13.00.00 and prior
ISaGRAF Workbench versions 6.0 through 6.6.9
Safety Instrumented System Workstation versions 1.2 and prior
Description
The issue is related to the deserialization of objects, which allows attackers to craft a malicious serialized object. If a local user opens this object in Connected Components Workbench, it may result in arbitrary code execution. This requires user interaction to be successfully exploited. The vulnerability is associated with the restoration of untrusted data in memory, potentially enabling an attacker to execute arbitrary code using a specially crafted file.
Recommendations
For Connected Components Workbench versions 13.00.00 and prior, consider disabling the deserialization of untrusted objects until a patch is available.
For ISaGRAF Workbench versions 6.0 through 6.6.9, restrict access to potentially malicious files to minimize the risk of exploitation.
For Safety Instrumented System Workstation versions 1.2 and prior, avoid using the affected software to open untrusted files until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connected Components Workbench
Isagraf Workbench
Safety Instrumented Systems Workstation