CVE-2018-10619
RSLinx Classic and FactoryTalk Linx Gateway - Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation.
Un elemento o ruta de búsqueda sin entrecomillar en RSLinx Classic en versiones 3.90.01 y anteriores y FactoryTalk Linx Gateway en versiones 3.90.00 y anteriores podría permitir que un usuario local autorizado sin privilegios ejecute código arbitrario y permita que un actor de amenaza escale sus privilegios de usuario en la estación de trabajo afectada.
Rockwell Automation RSLinx Classic and FactoryTalk Linx Gateway suffer from a privilege escalation vulnerability. Rockwell Automation RSLinx Classic versions 3.90.01, 3.73.00, 3.72.00, and 2.58.00 are susceptible. Rockwell Automation FactoryTalk Linx Gateway version 3.90.00 is susceptible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-01 CVE Reserved
- 2018-06-07 CVE Published
- 2024-05-17 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-428: Unquoted Search Path or Element
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104415 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-18-158-01 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/44892 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rockwellautomation Search vendor "Rockwellautomation" | Rslinx Classic Search vendor "Rockwellautomation" for product "Rslinx Classic" | < 3.90.01 Search vendor "Rockwellautomation" for product "Rslinx Classic" and version " < 3.90.01" | - |
Affected
| ||||||
Rockwellautomation Search vendor "Rockwellautomation" | Factorytalk Linx Gateway Search vendor "Rockwellautomation" for product "Factorytalk Linx Gateway" | < 3.90.00 Search vendor "Rockwellautomation" for product "Factorytalk Linx Gateway" and version " < 3.90.00" | - |
Affected
|