An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application. This could lead to uploading python files which can be later executed.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-216-01 | Third Party Advisory US Government Resource |
https://www.cisa.gov/uscert/ics/advisories/icsa-22-216-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 07:01
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 10.0 |
References | () https://www.cisa.gov/uscert/ics/advisories/icsa-22-216-01 - Third Party Advisory, US Government Resource |
Information
Published : 2022-08-10 20:15
Updated : 2024-11-21 07:01
NVD link : CVE-2022-2634
Mitre link : CVE-2022-2634
CVE.ORG link : CVE-2022-2634
JSON object : View
Products Affected
digi
- connectport_x2d_firmware
- connectport_x2d
CWE
CWE-250
Execution with Unnecessary Privileges