PT-2022-6466 · Unknown · Upsmon Pro

Michael Heinzl

·

Published

2022-08-10

·

Updated

2022-11-15

·

CVE-2022-38120

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions UPSMON PRO (affected versions not specified)
Description The issue is related to a path traversal vulnerability in the UPSMON PRO system, which can be exploited by a remote attacker with general user privileges to bypass authentication and access arbitrary system files. This vulnerability is associated with errors in processing relative paths to directories with limited access, allowing an attacker to circumvent security restrictions and gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-01568
CVE-2022-38120

Affected Products

Upsmon Pro