Directory Traversal in Project File Format allows overwrite (Zip Slip)
CVE-2022-45792

7.8HIGH

Key Information:

Vendor

Omron

Vendor
CVE Published:
22 January 2024

What is CVE-2022-45792?

A vulnerability exists in Omron PLC Engineering Software where project files can include malicious content. This issue enables an attacker to exploit directory traversal methods, potentially allowing the modification or overwriting of files on the filesystem. The exploitation of this vulnerability occurs with the same privileges as the logged-in user, raising significant security concerns for organizations utilizing this software. Proper validation and sanitization of project files are essential to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Sysmac Studio Windows 0 < 1.54.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.