Impact
The vulnerability in ControlFLASH arises from improper access control, specifically the installer granting write permissions to the Everyone group on the product’s installation directory. This weakness enables an attacker to place malicious files in the directory, leading to arbitrary code execution. Once executed, the attacker would run any commands or code at the permission level of the logged‑in user.
Affected Systems
Rockwell Automation’s ControlFLASH product is affected, specifically all installations up to and including version 15.07 as indicated by the product identifier cpe:2.3:a:rockwell_automation:controlflash_:v15.07_and_prior:*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, so the overall risk is substantial but not known to be actively exploited. The likely attack vector is local: an attacker with local access or the ability to run the installer could exploit the excessive write permissions to enable code execution at the user’s privilege level.
OpenCVE Enrichment