CVE-2021-27473
This type of vulnerability is also commonly referred to as a Zip Slip.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a Zip Slip. A local, authenticated attacker can create a malicious .ccwarc archive file that, when opened by Connected Components Workbench, will allow the attacker to gain the privileges of the software. If the software is running at SYSTEM level, the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- rockwellautomation/connected components workbench
- Source
- ics-cert@hq.dhs.gov
References
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131435Permissions Required, Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-133-01Third Party Advisory, US Government Resource
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1131435Permissions Required, Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-133-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.