FANUC has an update available to handle a path traversal vulnerability in its ROBOGUIDE-HandlingPRO, according to a report with CISA.

Successful exploitation of this remotely exploitable vulnerability, discovered by Yenting Lee of TXOne Networks, could allow an attacker to read and/or overwrite files on the system running the affected software.

The following versions of ROBOGUIDE-HandlingPRO, a robot simulation software, suffer from the issue: ROBOGUIDE-HandlingPRO: Versions 9 Rev.ZD and prior.

FANUC ROBOGUIDE-HandlingPRO Versions 9 Rev.ZD and prior is vulnerable to a path traversal, which could allow an attacker to remotely read files on the system running the affected software.

CVE-2023-1864 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.8.

Schneider Bold

The product sees use mainly in the critical manufacturing sector, and on a global basis.

No known public exploits specifically target this vulnerability. The vulnerability has a high attack complexity.

FANUC recommends users update to the latest version.

ISSSource

Pin It on Pinterest

Share This