← Back to CVE List

CVE-2022-2788

Published: 2022-08-19T21:15Z
Last Modified: 2024-11-21T07:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt