PT-2022-4942 · Unknown · Smart Evision

Gary Tan

+1

·

Published

2022-09-28

·

Updated

2022-09-28

·

CVE-2022-39033

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Smart eVision (affected versions not specified)
Description The issue is related to a path traversal vulnerability in Smart eVision's file acquisition function. This vulnerability is caused by insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access restricted paths, allowing them to download and delete arbitrary system files, which can disrupt service. The vulnerability can also be exploited to read, modify, or delete data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-06132
CVE-2022-39033

Affected Products

Smart Evision