CVE-2022-3156

A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:studio_5000_logix_emulate:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:18

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de ejecución remota de código en el software Rockwell Automation Studio 5000 Logix Emulate. A los usuarios se les otorgan permisos elevados sobre ciertos servicios del producto cuando se instala el software. Debido a esta mala configuración, un usuario malintencionado podría lograr la ejecución remota de código en el software de destino.
References () https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137846 - Vendor Advisory () https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137846 - Vendor Advisory

Information

Published : 2022-12-27 19:15

Updated : 2024-11-21 07:18


NVD link : CVE-2022-3156

Mitre link : CVE-2022-3156

CVE.ORG link : CVE-2022-3156


JSON object : View

Products Affected

rockwellautomation

  • studio_5000_logix_emulate
CWE
CWE-287

Improper Authentication