First published: Tue Jul 19 2022(Updated: )
A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user when opened or imported by the Safety Designer. This compromises confidentiality integrity and availability. For the attack to succeed a user must manually open a malicious project file.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Safety Designer | <=1.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27580 is a deserialization vulnerability in a .NET framework class used by Safety Designer versions up to and including 1.11.0.
CVE-2022-27580 allows an attacker to craft malicious project files that, when opened or imported in Sick Safety Designer versions up to and including 1.11.0, can execute arbitrary code with the privileges of the user running the software.
CVE-2022-27580 has a severity rating of 7.8 (High).
To fix CVE-2022-27580, it is recommended to update Sick Safety Designer to a version higher than 1.11.0.
You can find more information about CVE-2022-27580 on the official Sick website: https://sick.com/psirt.