PT-2022-24993 · Mz Automation+1 · Libiec61850+1
Mzillgit
·
Published
2021-09-23
·
Updated
2024-08-19
·
CVE-2022-3976
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MZ Automation libiec61850 versions up to 1.4
Description
A critical issue has been found in the MMS File Services component, specifically affecting the file src/mms/iso mms/client/mms client files.c. The manipulation of the
filename argument leads to path traversal. Upgrading to version 1.5 addresses this issue.Recommendations
For MZ Automation libiec61850 versions up to 1.4, upgrade to version 1.5 to resolve the issue. As a temporary workaround, consider restricting access to the
mms client files.c file until the upgrade is applied.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libiec61850