ICSA-22-088-01 Rockwell Automation ISaGRAF
CVE-2022-1018

5.5MEDIUM

Key Information:

Summary

When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.

Affected Version(s)

Connected Component Workbench All < 12

ISaGRAF All < 6.6.9

Safety Instrumented Systems Workstation All < 1.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kimiya of Trend Micro’s Zero Day Initiative reported this vulnerability to CISA.
.