Lucene search

K
nvd[email protected]NVD:CVE-2022-31218
HistoryJun 15, 2022 - 7:15 p.m.

CVE-2022-31218

2022-06-1519:15:11
CWE-59
web.nvd.nist.gov
3
vulnerabilities
drive composer
low-privileged attacker
file system
arbitrary content
installer file

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

16.3%

Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a “repair” operation on the product.

Affected configurations

Nvd
Node
abbautomation_builderRange1.1.02.5.0
OR
abbdrive_composerRange2.02.7.1entry
OR
abbdrive_composerRange2.02.7.1pro
OR
abbmint_workbenchRange5866
VendorProductVersionCPE
abbautomation_builder*cpe:2.3:a:abb:automation_builder:*:*:*:*:*:*:*:*
abbdrive_composer*cpe:2.3:a:abb:drive_composer:*:*:*:*:entry:*:*:*
abbdrive_composer*cpe:2.3:a:abb:drive_composer:*:*:*:*:pro:*:*:*
abbmint_workbench*cpe:2.3:a:abb:mint_workbench:*:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

16.3%

Related for NVD:CVE-2022-31218