Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
2022-06-15T19:15:11.367
2024-11-21T07:04:09.157
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | abb | automation_builder | ≤ 2.5.0 | Yes |
Application | abb | drive_composer | < 2.7.1 | Yes |
Application | abb | drive_composer | < 2.7.1 | Yes |
Application | abb | mint_workbench | ≤ 5866 | Yes |