ICSA-22-088-01 Rockwell Automation ISaGRAF
CVE-2022-1018
5.5MEDIUM
Summary
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
Affected Version(s)
Connected Component Workbench All < 12
ISaGRAF All < 6.6.9
Safety Instrumented Systems Workstation All < 1.1
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
kimiya of Trend Micro’s Zero Day Initiative reported this vulnerability to CISA.