PT-2022-25647 · Pilz · Pasvisu Server

CVE-2022-40977

·

Published

2022-11-24

·

Updated

2023-02-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pilz PASvisu Server versions prior to 1.12.0
Description A path traversal vulnerability was discovered, allowing an unauthenticated remote attacker to use a zipped, malicious configuration file to trigger arbitrary file writes, also known as 'zip-slip'. This issue does not affect confidentiality or availability.
Recommendations For versions prior to 1.12.0, update to version 1.12.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of zipped configuration files to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-40977

Affected Products

Pasvisu Server