Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-2465


Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.


Published

2022-08-25T18:15:10.223

Last Modified

2024-11-21T07:01:02.693

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation isagraf_workbench ≤ 6.6.9 Yes

References