Impact
The vulnerability originates from unquoted entries in the external tools configuration of Studio 5000 Logix Designer. Because the operating system does not properly handle paths containing spaces, it may resolve them to unintended executables that are encountered earlier in the search order. An attacker who can place a malicious executable in such a location could trigger its execution when the designer starts, resulting in arbitrary code execution with the permissions of the user running the application.
Affected Systems
The affected product is Rockwell Automation Studio 5000 Logix Designer. Version details are not provided in the advisory; any installation that includes the unquoted external tools configuration is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates a high risk of compromise. However, the EPSS score of < 1% signals a very low probability that this flaw is actively exploited at present. The flaw is not listed in CISA’s KEV catalog. The attack vector is likely a local or remote attacker who can place or influence files within a directory that is searched by the external tools configuration. Proper quoting of paths or removal of spaces would mitigate the problem.
OpenCVE Enrichment