CVE-2022-2464 is a Path Traversal vulnerability affecting Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9. An attacker can exploit this by crafting malicious files that, when opened by the workbench, allow traversal of the file system. This could lead to overwriting existing files and creating new ones with the same permissions as the software, requiring user interaction to succeed. With a CVSS score of 7.8 (HIGH), the attack vector is local with low complexity, but the potential impact on confidentiality, integrity, and availability is high. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, <= 6.6.9CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:isagraf_workbench:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.