7.8
CVSSv3

CVE-2018-10619

Published: 07/06/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation.

Vulnerable Product Search on Vulmon Subscribe to Product

rockwellautomation rslinx classic

rockwellautomation factorytalk linx gateway

Exploits

# Title: RSLinx Classic and FactoryTalk Linx Gateway - Privilege Escalation # Date: 2017-12-11 # Author: LiquidWorm # Vendor: Rockwell Automation, Inc # Product web page: wwwrockwellautomationcom # Affected version: Rockwell Automation RSLinx Classic 39001 # Rockwell Automation RSLinx Classic 37300 # R ...
Rockwell Automation RSLinx Classic and FactoryTalk Linx Gateway suffer from a privilege escalation vulnerability Rockwell Automation RSLinx Classic versions 39001, 37300, 37200, and 25800 are susceptible Rockwell Automation FactoryTalk Linx Gateway version 39000 is susceptible ...