ipDIO code execution | CVE-2022-22985
NAME
ipDIO code execution
- Platforms Affected:
IPCOMM ipDIO 3.9 2016/04/18
IPCOMM ipDIO SW 3.9 - Risk Level:
8.8 - Exploitability:
Unproven - Consequences:
Gain Access
DESCRIPTION
ipDIO could allow a remote attacker to execute arbitrary code on the system, caused by lack of filters when loading some sections in the web application. An attacker could exploit this vulnerability to inject and execute arbitrary code on the system.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Unavailable
MITIGATION
No remedy available as of March 3, 2022.
- Reference Link:
https://www.cisa.gov/uscert/ics/advisories/icsa-22-062-01 - Reference Link:
https://www.ipcomm.de/
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.