CVE-2022-3156

A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:studio_5000_logix_emulate:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:18

Type Values Removed Values Added
References () https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137846 - Vendor Advisory () https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137846 - Vendor Advisory

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software. A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software.

Information

Published : 2022-12-27 19:15

Updated : 2024-11-21 07:18


NVD link : CVE-2022-3156

Mitre link : CVE-2022-3156

CVE.ORG link : CVE-2022-3156


JSON object : View

Products Affected

rockwellautomation

  • studio_5000_logix_emulate
CWE
CWE-287

Improper Authentication