PT-2021-6880 · Unknown · Isagraf Workbench+2

Kimiya

·

Published

2021-10-21

·

Updated

2022-05-26

·

CVE-2022-1118

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Connected Components Workbench versions 13.00.00 and prior ISaGRAF Workbench versions 6.0 through 6.6.9 Safety Instrumented System Workstation versions 1.2 and prior
Description The issue is related to the deserialization of objects, which allows attackers to craft a malicious serialized object. If a local user opens this object in Connected Components Workbench, it may result in arbitrary code execution. This requires user interaction to be successfully exploited. The vulnerability is associated with the restoration of untrusted data in memory, potentially enabling an attacker to execute arbitrary code using a specially crafted file.
Recommendations For Connected Components Workbench versions 13.00.00 and prior, consider disabling the deserialization of untrusted objects until a patch is available. For ISaGRAF Workbench versions 6.0 through 6.6.9, restrict access to potentially malicious files to minimize the risk of exploitation. For Safety Instrumented System Workstation versions 1.2 and prior, avoid using the affected software to open untrusted files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02430
CVE-2022-1118
ZDI-22-586
ZDI-22-587
ZDI-22-588
ZDI-22-589

Affected Products

Connected Components Workbench
Isagraf Workbench
Safety Instrumented Systems Workstation