When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-24368 When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
Fixes

Solution

Rockwell Automation encourages users to update to the available software revisions below: Connected Component Workbench: Update to v13.00 ISaGRAF Workbench: For now, use mitigations listed until a patch is released. More mitigation actions are planned. Safety Instrumented Systems Workstation: Update to v1.2


Workaround

If an upgrade is not possible or available, users should apply the following mitigations: Run Connected Components Workbench as a User, not as an Administrator, to minimize the impact of malicious code on the infected system. Do not open untrusted files with Connected Component Workbench, ISaGRAF, SISW. Employ training and awareness programs to educate users on the warning signs of a phishing or social engineering attack. Use Microsoft AppLocker or other similar allow list application to help mitigate risk. Information on using AppLocker with Rockwell Automation products is available at KnowledgeBase Article QA17329 Ensure the least-privilege user principle is followed, and user/service account access to shared resources (such as a database) is only granted with a minimum number of rights as needed.

History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:32:28.157Z

Reserved: 2022-03-17T00:00:00.000Z

Link: CVE-2022-1018

cve-icon Vulnrichment

Updated: 2024-08-02T23:47:42.899Z

cve-icon NVD

Status : Modified

Published: 2022-04-01T23:15:12.177

Modified: 2024-11-21T06:39:52.100

Link: CVE-2022-1018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.