Command Injection Vulnerability in CX-Supervisor by Mitsubishi Electric
CVE-2018-19015

7.3HIGH

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
28 January 2019

What is CVE-2018-19015?

A command injection vulnerability exists in CX-Supervisor, affecting versions 3.42 and prior. An attacker can exploit this vulnerability by crafting a malicious project file, which can trigger the execution of arbitrary commands. This may result in unauthorized code execution, allowing attackers to create, read, and write files under the application's privileges, posing significant risks to system integrity and data confidentiality.

Affected Version(s)

CX-Supervisor Versions 3.42 and prior

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.