Description
An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary code within the context of the host machine.
Problem types
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Product status
v1.6.0.10
v1.7.1
Credits
Vera Mens and Noam Moshe of Claroty Team82 reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-308-05