CVE-2022-2463

MEDIUM

Rockwell Automation ISaGRAF Workbench 6.0-6.6.9 - Path Traversal via Malicious .7z Exchange File

Title source: llm
STIX 2.1

Description

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running at the SYSTEM level, then the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.

References (1)

Core 1
Core References
Mitigation, Patch, Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-202-03

Scores

CVSS v3 6.1
EPSS 0.0007
EPSS Percentile 20.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
rockwellautomation/isagraf_workbench 6.0 - 6.6.9
Published Aug 25, 2022
Tracked Since Feb 18, 2026