First published: Fri Aug 19 2022(Updated: )
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Electric\'s Proficy | <=9.80 | |
Emerson Proficy Machine Edition Version 9.80 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-2788.
The severity of CVE-2022-2788 is high with a severity value of 7.3.
The CWE ID for this vulnerability is CWE-29.
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is affected.
The vulnerability allows attackers to implant a malicious .BLZ file on the PLC through a path traversal attack known as ZipSlip.