Rockwell Automation Connected Components Workbench Deserialization of Untrusted Data
CVE-2021-27475
8.6HIGH
Key Information:
- Vendor
- Rockwell Automation
- Vendor
- CVE Published:
- 23 March 2022
Summary
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.
Affected Version(s)
Connected Components Workbench <= unspecified
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mashav Sapir of Claroty reported these vulnerabilities to Rockwell Automation.