PT-2022-3170 · Unknown · Pacsystems

Published

2022-06-22

·

Updated

2022-06-22

·

CVE-2022-30265

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PACsystems (affected versions not specified)
Description The issue is related to insufficient data authentication in the PACsystems programmable logic controller software. It allows a remote attacker to execute arbitrary code using a specially crafted file written in C or IEC 61131-3 programming languages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03850
CVE-2022-30265

Affected Products

Pacsystems