CVE-2022-31218
15.06.2022, 19:15
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
Vendor | Product | Version |
---|---|---|
abb | automation_builder | 1.1.0 ≤ 𝑥 ≤ 2.5.0 |
abb | drive_composer | 2.0 ≤ 𝑥 < 2.7.1 |
abb | drive_composer | 2.0 ≤ 𝑥 < 2.7.1 |
abb | mint_workbench | 𝑥 ≤ 5866 |
𝑥
= Vulnerable software versions
References