RoboDK versions 5.5.3 and prior contain an insecure permission assignment to critical directories vulnerability, which could allow a local user to escalate privileges and write files to the RoboDK process and achieve code execution.
Workaround:
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-01 | third party advisory us government resource |
https://robodk.com/contact | product |