CVE-2022-34836

Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities such as the start and stop of various activity and the last error code etc.
Configurations

Configuration 1 (hide)

cpe:2.3:a:abb:zenon:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:10

Type Values Removed Values Added
References () https://search.abb.com/library/Download.aspx?DocumentID=2NGA001479&LanguageCode=en&DocumentPartId=&Action=Launch - Vendor Advisory () https://search.abb.com/library/Download.aspx?DocumentID=2NGA001479&LanguageCode=en&DocumentPartId=&Action=Launch - Vendor Advisory
CVSS v2 : unknown
v3 : 8.2
v2 : unknown
v3 : 5.9

Information

Published : 2022-08-24 16:15

Updated : 2024-11-21 07:10


NVD link : CVE-2022-34836

Mitre link : CVE-2022-34836

CVE.ORG link : CVE-2022-34836


JSON object : View

Products Affected

abb

  • zenon
CWE
CWE-23

Relative Path Traversal

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')