Rockwell Automation Studio 5000 Logix Designer
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*
- 36.00.02
An arbitrary code execution vulnerability has been identified in Rockwell Automation's Studio 5000 Logix Designer, versions 36.00.02 prior to 37.00.02. This vulnerability arises from improper handling of environment variables, which could potentially allow the execution of malicious code without causing the application to crash. However, if the specified path does not contain a valid file, Logix Designer will crash.
Exploitation of this vulnerability could lead to arbitrary code execution within the application.
Users are advised to update to version 37.00.02 or later. For those unable to upgrade, security best practices should be followed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.