PT-2022-15176 · Unknown · Dxl Broker

Published

2022-11-07

·

Updated

2023-08-08

·

CVE-2022-2188

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions DXL Broker for Windows versions prior to 6.0.0.280
Description The issue allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory, potentially leading to a denial-of-service attack on the DXL Broker.
Recommendations For versions prior to 6.0.0.280, update to version 6.0.0.280 or later to resolve the issue. As a temporary workaround, consider restricting access to the logs directory to minimize the risk of exploitation.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2022-2188

Affected Products

Dxl Broker