PT-2022-3551 · Da50N · Da50N
Ron Brash
·
Published
2022-04-14
·
Updated
2022-04-29
·
CVE-2022-26516
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
DA50N (affected versions not specified)
Description
The issue is related to insufficient authentication of data in the web interface, which may allow a remote attacker to execute arbitrary code by uploading a specially crafted image. Authorized users may inadvertently install a maliciously modified package file when updating the device via the web user interface, potentially using a package file obtained from an unauthorized source or a file that was compromised between download and deployment.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Da50N