Lucene search

K
cveIcscertCVE-2022-2102
HistoryJun 24, 2022 - 3:15 p.m.

CVE-2022-2102

2022-06-2415:15:10
CWE-841
CWE-434
icscert
web.nvd.nist.gov
38
8
cve-2022-2102
information security
file upload
bypass
php scripts
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

EPSS

0.001

Percentile

30.7%

Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.

Affected configurations

Nvd
Node
secheronsepcos_control_and_protection_relayMatch-
AND
secheronsepcos_control_and_protection_relay_firmwareRange1.23.01.23.21
OR
secheronsepcos_control_and_protection_relay_firmwareRange1.24.01.24.8
OR
secheronsepcos_control_and_protection_relay_firmwareRange1.25.01.25.3
VendorProductVersionCPE
secheronsepcos_control_and_protection_relay-cpe:2.3:h:secheron:sepcos_control_and_protection_relay:-:*:*:*:*:*:*:*
secheronsepcos_control_and_protection_relay_firmware*cpe:2.3:o:secheron:sepcos_control_and_protection_relay_firmware:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "SEPCOS Control and Protection Relay firmware package",
    "vendor": "Secheron",
    "versions": [
      {
        "changes": [
          {
            "at": "1.24.8",
            "status": "unaffected"
          },
          {
            "at": "1.25.3",
            "status": "unaffected"
          }
        ],
        "lessThan": "1.23.21",
        "status": "affected",
        "version": "All versions",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

EPSS

0.001

Percentile

30.7%

Related for CVE-2022-2102