CVE-2022-2465: ISaGRAF Workbench Deserialization of Untrusted Data CWE-502
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2465?
CVE-2022-2465 is classified as a high severity vulnerability due to its potential to allow attackers to execute arbitrary code.
How do I fix CVE-2022-2465?
To fix CVE-2022-2465, update Rockwell Automation ISaGRAF Workbench to a version higher than 6.6.9.
Which versions of ISaGRAF Workbench are affected by CVE-2022-2465?
CVE-2022-2465 affects ISaGRAF Workbench versions 6.0 through 6.6.9.
What type of vulnerability is CVE-2022-2465?
CVE-2022-2465 is a Deserialization of Untrusted Data vulnerability.
What can attackers do with CVE-2022-2465?
Attackers can exploit CVE-2022-2465 to craft and execute malicious serialized objects, potentially leading to arbitrary code execution.