CVE-2022-1018
01.04.2022, 23:15
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.Enginsight
Vendor | Product | Version |
---|---|---|
rockwellautomation | connected_components_workbench | 𝑥 ≤ 12.0 |
rockwellautomation | isagraf | 𝑥 ≤ 6.6.9 |
rockwellautomation | safety_instrumented_systems_workstation | 𝑥 ≤ 1.1 |
𝑥
= Vulnerable software versions