CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
21.7%
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes (‘zip-slip’). File writes do not affect confidentiality or availability.
Vendor | Product | Version | CPE |
---|---|---|---|
pilz | pss_4000 | - | cpe:2.3:h:pilz:pss_4000:-:*:*:*:*:*:*:* |
pilz | pas_4000 | * | cpe:2.3:o:pilz:pas_4000:*:*:*:*:*:*:*:* |
pliz | pascal | * | cpe:2.3:a:pliz:pascal:*:*:*:*:*:*:*:* |
pliz | pasconnect | * | cpe:2.3:a:pliz:pasconnect:*:*:*:*:*:*:*:* |
pliz | pasmotion | * | cpe:2.3:a:pliz:pasmotion:*:*:*:*:*:*:*:* |
pliz | pnozmulti_configurator | * | cpe:2.3:a:pliz:pnozmulti_configurator:*:*:*:*:long_term_support:*:*:* |
pliz | pnozmulti_configurator | * | cpe:2.3:a:pliz:pnozmulti_configurator:*:*:*:*:-:*:*:* |
[
{
"defaultStatus": "unaffected",
"product": "PAScal",
"vendor": "PILZ",
"versions": [
{
"lessThanOrEqual": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "PASconnect",
"vendor": "PILZ",
"versions": [
{
"lessThan": "1.4.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "PASmotion",
"vendor": "PILZ",
"versions": [
{
"lessThan": "1.4.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "PNOZmulti Configurator",
"vendor": "PILZ",
"versions": [
{
"lessThan": "11.2.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "PNOZmulti Configurator LTS",
"vendor": "PILZ",
"versions": [
{
"lessThan": "10.14.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "PAS4000",
"vendor": "PILZ",
"versions": [
{
"lessThan": "1.25.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
]
More
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
21.7%