漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Studio 5000 Logix Designer® – Multiple Vulnerabilities
Vulnerability Description
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Rockwell Automation Studio 5000 Logix Designer 路径遍历漏洞
Vulnerability Description
Rockwell Automation Studio 5000 Logix Designer是美国Rockwell Automation基金会的一款自动化控制编程软件。 Rockwell Automation Studio 5000 Logix Designer存在路径遍历漏洞,该漏洞源于对ACD项目文件中的文件路径限制不当,导致路径遍历。以下版本受到影响:V36.00版本、35.00版本、35.01版本、34.00至34.03版本、33.00至33.03版本、32.00至32.04版本和更早版本。
CVSS Information
N/A
Vulnerability Type
N/A