CVE-2013-5022: Path Traversal
Absolute path traversal vulnerability in the 3D Graph ActiveX control in cw3dgrph.ocx in National Instruments LabWindows/CVI 2012 SP1 and earlier, LabVIEW 2012 SP1 and earlier, and other products allows remote attackers to create and execute arbitrary files via a full pathname in an argument to the ExportStyle method, in conjunction with file content in the (1) Caption or (2) FormatString property value.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5022?
CVE-2013-5022 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2013-5022?
The fix for CVE-2013-5022 involves upgrading to a patched version of the affected software, specifically versions later than LabWindows/CVI 2012 SP1, LabVIEW 2012 SP1, and the respective versions of Measurement Studio and TestStand.
What products are affected by CVE-2013-5022?
CVE-2013-5022 affects National Instruments LabVIEW, LabWindows/CVI, Measurement Studio, and TestStand versions up to and including 2012 SP1.
What type of vulnerability is CVE-2013-5022?
CVE-2013-5022 is an absolute path traversal vulnerability that allows attackers to execute arbitrary files.
Can CVE-2013-5022 be exploited remotely?
Yes, CVE-2013-5022 can be exploited remotely by attackers who can manipulate input to the vulnerable ActiveX control.