PT-2021-7290 · Rockwell Automation · Rockwell Automation Connected Components Workbench

Mashav Sapir

·

Published

2021-05-13

·

Updated

2022-03-29

·

CVE-2021-27471

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation Connected Components Workbench versions prior to 12.00.00
Description The issue is related to the parsing mechanism of certain file types, which lacks input sanitization for file paths. This could allow an attacker to create malicious files that can traverse the file system when opened, potentially overwriting existing files and creating new ones with the same permissions as the software. Exploitation requires user interaction.
Recommendations For versions prior to 12.00.00, consider restricting access to file system operations until a patch is available. As a temporary workaround, avoid opening files from untrusted sources to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05265
CVE-2021-27471

Affected Products

Rockwell Automation Connected Components Workbench