PT-2022-4942 · Unknown · Smart Evision
Gary Tan
+1
·
Published
2022-09-28
·
Updated
2022-09-28
·
CVE-2022-39033
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Smart eVision (affected versions not specified)
Description
The issue is related to a path traversal vulnerability in Smart eVision's file acquisition function. This vulnerability is caused by insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access restricted paths, allowing them to download and delete arbitrary system files, which can disrupt service. The vulnerability can also be exploited to read, modify, or delete data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smart Evision