CVE-2022-2788: Path Traversal
Published Aug 19, 2022
·Updated
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.
Affected Software
2 affected components
Emerson Proficy Machine Edition Version 9.80 and prior
Emerson Electric\'s Proficy<=9.80
Event History
Aug 19, 2022
CVE Published
via MITRE·08:56 PM
Data Sourced
via MITRE·08:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-2788.
2
What is the severity of CVE-2022-2788?
The severity of CVE-2022-2788 is high with a severity value of 7.3.
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-29.
4
What version of Emerson Electric's Proficy Machine Edition is affected?
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is affected.
5
How does the vulnerability allow attackers to implant a malicious file?
The vulnerability allows attackers to implant a malicious .BLZ file on the PLC through a path traversal attack known as ZipSlip.