PT-2021-7290 · Rockwell Automation · Rockwell Automation Connected Components Workbench
Mashav Sapir
·
Published
2021-05-13
·
Updated
2022-03-29
·
CVE-2021-27471
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation Connected Components Workbench versions prior to 12.00.00
Description
The issue is related to the parsing mechanism of certain file types, which lacks input sanitization for file paths. This could allow an attacker to create malicious files that can traverse the file system when opened, potentially overwriting existing files and creating new ones with the same permissions as the software. Exploitation requires user interaction.
Recommendations
For versions prior to 12.00.00, consider restricting access to file system operations until a patch is available. As a temporary workaround, avoid opening files from untrusted sources to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rockwell Automation Connected Components Workbench