Rockwell Automation Studio 5000 Logix Designer
Summary
Multiple vulnerabilities have been identified in Rockwell Automation Studio 5000 Logix Designer, allowing local attackers to execute arbitrary files, alter configurations, or execute arbitrary code. These vulnerabilities include path traversal, incorrect authorization, and unquoted search path elements, with the most severe impacting versions as far back as V32.00.
IFF Assessment
The identification of multiple vulnerabilities that allow for arbitrary code execution and configuration alteration represents a significant risk to industrial control systems, making it bad news for defenders.
Severity
The CVSS score of 7.5 indicates a High severity vulnerability. This is likely due to factors such as the ability to execute arbitrary code, the potential impact on critical infrastructure, and the local attack vector.
Defender Context
Defenders should prioritize patching or mitigating these vulnerabilities in Rockwell Automation Studio 5000 Logix Designer, especially in critical manufacturing environments. The ability for local attackers to achieve code execution means that compromised credentials or local access can lead to severe system compromise.