nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-45792 CVE-2022-45792
HIGH
Directory Traversal in Project File Format allows overwrite (Zip Slip)
Record summary
CVE-2022-45792 has a selected CVSS score of 7.8 (high).
Description
Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Sysmac StudioBrowse Omron / Sysmac StudioDefault status: unaffected | CVE List | Before 1.54.0 | affected |
References
2dragos.com
https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-file-format-access