CVE-2022-1261: Matrikon OPC Server Improper Access Control
Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to the OPC server to use the functions of the IPersisFile to execute operating system processes with system-level privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for Matrikon OPC Server?
The vulnerability ID for Matrikon OPC Server is CVE-2022-1261.
What is the severity of CVE-2022-1261?
The severity of CVE-2022-1261 is critical (8.8).
Which software versions of Matrikon OPC Server are affected?
All versions of Matrikon OPC Server are affected.
How can a low privileged user exploit CVE-2022-1261?
A low privileged user can exploit CVE-2022-1261 by connecting to the OPC server and using the functions of the IPersisFile to execute operating system processes with system-level privileges.
Is there a fix available for CVE-2022-1261?
The vendor has not provided a fix for CVE-2022-1261 yet. It is recommended to apply mitigations or follow the guidance provided by the vendor or cybersecurity authorities.