PT-2022-4139 · Rockwell Automation · Isagraf Workbench

Mashav Sapir

·

Published

2022-07-21

·

Updated

2022-08-27

·

CVE-2022-2464

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9
Description The issue is related to a Path Traversal vulnerability, where crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF Workbench. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the ISaGRAF Workbench software. User interaction is required for this exploit to be successful. The vulnerability is also associated with incorrect restriction of the directory path name with limited access, which can allow an attacker to elevate their privileges using a specially crafted malicious file.
Recommendations For Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9, consider disabling the ability to open crafted malicious files until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation. Avoid using the ISaGRAF Workbench software to open files from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-04982
CVE-2022-2464

Affected Products

Isagraf Workbench