CVE-2022-3156

A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:studio_5000_logix_emulate:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software. A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software.

06 Jan 2023, 14:34

Type Values Removed Values Added
References (MISC) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137846 - (MISC) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137846 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-287
CPE cpe:2.3:a:rockwellautomation:studio_5000_logix_emulate:*:*:*:*:*:*:*:*
First Time Rockwellautomation
Rockwellautomation studio 5000 Logix Emulate

27 Dec 2022, 19:59

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-27 19:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-3156

Mitre link : CVE-2022-3156

CVE.ORG link : CVE-2022-3156


JSON object : View

Products Affected

rockwellautomation

  • studio_5000_logix_emulate
CWE
CWE-287

Improper Authentication