CVE-2022-1018: ICSA-22-088-01 Rockwell Automation ISaGRAF
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1018?
CVE-2022-1018 has a severity rating of critical due to the potential for remote data exfiltration.
How do I fix CVE-2022-1018?
To remediate CVE-2022-1018, update the affected software to the latest version that addresses this vulnerability.
What software is affected by CVE-2022-1018?
CVE-2022-1018 affects Rockwell Automation's Connected Components Workbench, Isagraf, and Safety Instrumented Systems Workstation products.
What can an attacker achieve by exploiting CVE-2022-1018?
An attacker exploiting CVE-2022-1018 could potentially exfiltrate sensitive data from local files to a remote server.
Is there a workaround for CVE-2022-1018 until a patch is applied?
A workaround for CVE-2022-1018 involves avoiding the opening of untrusted or malicious solution files.