CVE-2022-22525
Command injection in restore function of Carlo Gavazzi UWP3.0 allows for command injection
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Carlo Gavazzi · CPY Car Park ServerCarlo Gavazzi · UWP 3.0 Monitoring Gateway and ControllerCarlo Gavazzi · UWP 3.0 Monitoring Gateway and Controller – EDP versionCarlo Gavazzi · UWP 3.0 Monitoring Gateway and Controller – Security EnhancedQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →