Command Injection Vulnerability in CX-Supervisor by Mitsubishi Electric
CVE-2018-19015
7.3HIGH
What is CVE-2018-19015?
A command injection vulnerability exists in CX-Supervisor, affecting versions 3.42 and prior. An attacker can exploit this vulnerability by crafting a malicious project file, which can trigger the execution of arbitrary commands. This may result in unauthorized code execution, allowing attackers to create, read, and write files under the application's privileges, posing significant risks to system integrity and data confidentiality.
Affected Version(s)
CX-Supervisor Versions 3.42 and prior
