CVE-2022-31219
published 2022-06-15CVE-2022-31219: Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.5th percentile
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | abb_automation_builder | >= 1.1.0 < unspecified | unspecified |
| abb | abb_automation_builder | unspecified – 2.5.0 | — |
| abb | automation_builder | 1.1.0 – 2.5.0 | — |
| abb | drive_composer | >= 2.0 < 2.7.1 | 2.7.1 |
| abb | drive_composer_entry | >= 2.0 < unspecified | unspecified |
| abb | drive_composer_entry | unspecified – 2.7 | — |
| abb | drive_composer_pro | >= 2.0 < unspecified | unspecified |
| abb | drive_composer_pro | unspecified – 2.7 | — |
| abb | mint_workbench | <= 5866 | — |
| abb | mint_workbench | build – 5866 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mgwv-57p9-8v74: Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitra
ghsa_unreviewed·2022-06-16
CVE-2022-31219 [HIGH] CWE-269 GHSA-mgwv-57p9-8v74: Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitra
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
CISA ICS
ABB Drive Composer, Automation Builder, Mint Workbench
cisa_ics·2022-07-26·CVSS 7.8
[HIGH] ABB Drive Composer, Automation Builder, Mint Workbench
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB Drive Composer, Automation Builder, Mint Workbench
Last RevisedJuly 26, 2022
Alert CodeICSA-22-202-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: ABB
- Equipment: Drive Composer, Automation Builder, Mint Workbench
- Vulnerability: Improper Privilege Management
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following ABB products are affected:
- ABB Drive Composer Entry: Versions 2.0 to 2.7
- ABB Drive Composer Pro: Ver
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://search.abb.com/library/Download.aspx?DocumentID=9AKK108467A0305&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.38192870.478847987.1655218701-372504397.1647012599https://search.abb.com/library/Download.aspx?DocumentID=9AKK108467A0305&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.38192870.478847987.1655218701-372504397.1647012599
2022-06-15
Published