CVE-2018-10619

HIGH

RSLinx Classic <3.90.01 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation.

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · textlocalwindows
https://www.exploit-db.com/exploits/44892

References (3)

Core 3
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44892/
Third Party Advisory, US Government Resource, VDB Entry x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-158-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104415

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 6.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (2)
rockwellautomation/factorytalk_linx_gateway < 3.90.00
rockwellautomation/rslinx_classic < 3.90.01
Published Jun 07, 2018
Tracked Since Feb 18, 2026