In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-668
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| codesys | development_system | * | <built-in method update of dict object at 0x7e61114e0f80> | Application |
| codesys | scripting | * | <built-in method update of dict object at 0x7e60e8c7d9c0> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:codesys:development_system:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:codesys:scripting:*:*:*:*:*:*:*:* |