SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-27473

This type of vulnerability is also commonly referred to as a Zip Slip.

HIGH 8.2EPSS 0.78%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a Zip Slip. A local, authenticated attacker can create a malicious .ccwarc archive file that, when opened by Connected Components Workbench, will allow the attacker to gain the privileges of the software. If the software is running at SYSTEM level, the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.

CVSS 3.1
8.2 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS
0.78% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
rockwellautomation/connected components workbench
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.