ICSA-22-088-01 Rockwell Automation ISaGRAF
Vulnerability Description
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-1018
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- kimiya of Trend Micro’s Zero Day Initiative reported this vulnerability to CISA.
More from Rockwell Automation
View All →Affected Vendor
Rockwell Automation
View all reports →