PT-2022-4139 · Rockwell Automation · Isagraf Workbench
Mashav Sapir
·
Published
2022-07-21
·
Updated
2022-08-27
·
CVE-2022-2464
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9
Description
The issue is related to a Path Traversal vulnerability, where crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF Workbench. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the ISaGRAF Workbench software. User interaction is required for this exploit to be successful. The vulnerability is also associated with incorrect restriction of the directory path name with limited access, which can allow an attacker to elevate their privileges using a specially crafted malicious file.
Recommendations
For Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9, consider disabling the ability to open crafted malicious files until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation. Avoid using the ISaGRAF Workbench software to open files from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Isagraf Workbench