PT-2022-25647 · Pilz · Pasvisu Server

Published

2022-11-24

·

Updated

2023-02-01

·

CVE-2022-40977

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pilz PASvisu Server versions prior to 1.12.0
Description A path traversal vulnerability was discovered, allowing an unauthenticated remote attacker to use a zipped, malicious configuration file to trigger arbitrary file writes, also known as 'zip-slip'. This issue does not affect confidentiality or availability.
Recommendations For versions prior to 1.12.0, update to version 1.12.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of zipped configuration files to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-40977

Affected Products

Pasvisu Server