CVE-2022-27579 is a deserialization vulnerability in Flexi Soft Designer versions up to and including 1.9.4 SP1, allowing attackers to craft malicious project files. Opening such a file executes arbitrary code with the user's privileges, compromising confidentiality, integrity, and availability. This vulnerability has a CVSS score of 7.8 (High) due to its local attack vector and low complexity, requiring user interaction to open a malicious file. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.4CPE matchmatch criteria | cpe:2.3:a:sick:flexi_soft_designer:*:*:*:*:*:*:*:* | ||
1.9.4CPE matchmatch criteria | cpe:2.3:a:sick:flexi_soft_designer:1.9.4:-:*:*:*:*:*:* | ||
1.9.4CPE matchmatch criteria | cpe:2.3:a:sick:flexi_soft_designer:1.9.4:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
SafeLogic Designer vulnerabilities
Aug 11, 2022SafeLogic Designer vulnerabilities
Aug 11, 2022SafeLogic Designer vulnerabilities
Aug 11, 2022SafeLogic Designer vulnerabilities
Aug 11, 2022