Vulnerability Description
Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Omron | Automation Software Sysmac Studio | <= 1.54 |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-04Third Party AdvisoryUS Government Resource
- https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-fThird Party Advisory
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-009_en.pdfVendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-262-04Third Party AdvisoryUS Government Resource
- https://www.dragos.com/advisory/omron-plc-and-engineering-software-network-and-fThird Party Advisory
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-009_en.pdfVendor Advisory
FAQ
What is CVE-2022-45793?
CVE-2022-45793 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a dif...
How severe is CVE-2022-45793?
CVE-2022-45793 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-45793?
Check the references section above for vendor advisories and patch information. Affected products include: Omron Automation Software Sysmac Studio.