CVE-2022-1018
Published: Apr 1, 2022
Modified: Apr 16, 2025
CVSS v3.1
5.5
Description
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
| Vendor | Product | Versions |
|---|---|---|
Rockwell Automation | Connected Component Workbench | affected All - < 12 |
Rockwell Automation | ISaGRAF | affected All - < 6.6.9 |
Rockwell Automation | Safety Instrumented Systems Workstation | affected All - < 1.1 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now