PT-2022-23822 · Carel · Carel Pcoweb Hvac Bacnet Gateway

·

CVE-2022-37122

·

Published

2022-08-31

·

Updated

2025-10-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Carel pCOWeb HVAC BACnet Gateway versions 2.1.0, Firmware A2.1.0 through B2.1.0, Application Software 2.15.4A Software v16 13020200
Description The Carel pCOWeb HVAC BACnet Gateway is affected by an unauthenticated arbitrary file disclosure issue. Input provided through the file GET parameter to the logdownload.cgi Bash script is not sufficiently validated before being used to download log files. This allows for the disclosure of arbitrary and sensitive files through directory traversal attacks.
Recommendations Carel pCOWeb HVAC BACnet Gateway version 2.1.0, Firmware A2.1.0 through B2.1.0, and Application Software 2.15.4A Software v16 13020200: Ensure proper validation of the file parameter in the logdownload.cgi script to prevent directory traversal.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-37122

Affected Products

Carel Pcoweb Hvac Bacnet Gateway