HIGH

CVE-2022-1118

CVSS v3

7.8

HIGH

EPSS Score

51.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. This allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in arbitrary code execution. This vulnerability requires user interaction to be successfully exploited

Technical details

Published
5/17/2022

Frequently asked questions

What is CVE-2022-1118?

Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. This allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in arbitrary code execution. This vulnerability requires user interaction to be successfully exploited

Is CVE-2022-1118 actively exploited?

Active exploitation of CVE-2022-1118 has not been confirmed. The EPSS score is 51.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-1118?

CVE-2022-1118 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2022-1118 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.