CVE-2022-1118 Information
Jun 07, 2022
cve
Description
Connected Components Workbench (v13.00.00 and prior) ISaGRAF Workbench (v6.0 though v6.6.9) and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. This allows attackers to craft a malicious serialized object that if opened by a local user in Connected Components Workbench may result in arbitrary code execution. This vulnerability requires user interaction to be successfully exploited
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://www.cisa.gov/uscert/ics/advisories/icsa-22-095-01
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: