CVE Database
/

CVE-2022-1118

Back to search

CVE-2022-1118

Published: May 17, 2022

Modified: Apr 16, 2025

PUBLISHED

CVSS v3.1

8.6

HIGH

Description

Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. This allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in arbitrary code execution. This vulnerability requires user interaction to be successfully exploited

VendorProductVersions

Rockwell Automation

Connected Component Workbench

affected
All - <= v13.00.00

Rockwell Automation

ISaGRAF Workbench

affected
All v6.0 through v6.6.9

Rockwell Automation

Safety Instrumented Systems Workstation

affected
All - <= v1.2 (for Trusted Controllers)

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now