CVE-2022-2561 is a remote code execution vulnerability affecting OPC Labs QuickOPC 2022.1, specifically within the Connectivity Explorer's XML file processing. It stems from improper validation of user-supplied data, leading to untrusted data deserialization. Exploitation requires user interaction, where a target must visit a malicious page or open a malicious file. This vulnerability carries a CVSS score of 7.8 (High), indicating a high potential for impact, allowing an attacker to execute arbitrary code in the context of the current process. The attack complexity is low, but user interaction is required. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules for Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.63, < 5.63.246CPE matchmatch criteria | cpe:2.3:a:opclabs:quickopc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.