Vulnerability Details CVE-2022-31218
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.9%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2022-31218
-
cpe:2.3:a:abb:automation_builder:1.1.0
-
cpe:2.3:a:abb:automation_builder:1.1.1
-
cpe:2.3:a:abb:automation_builder:1.1.2
-
cpe:2.3:a:abb:automation_builder:1.2.0
-
cpe:2.3:a:abb:automation_builder:1.2.1
-
cpe:2.3:a:abb:automation_builder:1.2.2
-
cpe:2.3:a:abb:automation_builder:1.2.3
-
cpe:2.3:a:abb:automation_builder:1.2.4
-
cpe:2.3:a:abb:automation_builder:2.0.3
-
cpe:2.3:a:abb:automation_builder:2.0.4
-
cpe:2.3:a:abb:automation_builder:2.1.1
-
cpe:2.3:a:abb:automation_builder:2.1.2
-
cpe:2.3:a:abb:automation_builder:2.2.1
-
cpe:2.3:a:abb:automation_builder:2.2.2
-
cpe:2.3:a:abb:automation_builder:2.2.3
-
cpe:2.3:a:abb:automation_builder:2.2.4
-
cpe:2.3:a:abb:automation_builder:2.2.5
-
cpe:2.3:a:abb:automation_builder:2.3.0
-
cpe:2.3:a:abb:automation_builder:2.4.1
-
cpe:2.3:a:abb:automation_builder:2.5.0
-
cpe:2.3:a:abb:drive_composer:2.0
-
cpe:2.3:a:abb:drive_composer:2.7
-
cpe:2.3:a:abb:mint_workbench:-
-
cpe:2.3:a:abb:mint_workbench:5866