PT-2022-3528 · Unknown · Sepcos Single Package

Anthony Candarini

+3

·

Published

2022-06-16

·

Updated

2022-07-06

·

CVE-2022-2102

CVSS v3.1

9.7

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions SEPCOS Single Package (affected versions not specified)
Description The issue is related to the bypassing of controls that limit uploads to certain file extensions. This could allow an attacker to intercept and modify the initial file upload page response, enabling arbitrary file upload into locations where PHP scripts may be executed. The vulnerability may also be related to the incorrect implementation of the sequence of actions in the SEPCOS Single Package firmware upload handler, potentially allowing a remote attacker to upload arbitrary files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04311
CVE-2022-2102

Affected Products

Sepcos Single Package