Impact
Studio 5000 Logix Designer allows improper path validation when opening ACD project files, enabling path traversal and arbitrary file writes. An attacker can craft a malicious ACD file that causes the software to write files to locations outside the intended extraction directory, which may lead to the execution of attacker‑controlled code. This weakness aligns with CWE‑22, the path traversal vulnerability type.
Affected Systems
All versions of Rockwell Automation’s Studio 5000 Logix Designer are affected because the description does not specify a version subset. The flaw resides in the project opening routine that processes ACD files across the product line.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity vulnerability, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The flaw is not listed in the CISA KEV catalog. Exploitation requires a user to open a crafted ACD file, so the attack vector is local and depends on an attacker gaining the victim’s ability to run Studio 5000 Logix Designer with the malicious file.
OpenCVE Enrichment