CVE-2022-34825: Critical severity nec expresscluster x vulnerability
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system and to potentially execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is vulnerability CVE-2022-34825?
CVE-2022-34825 is an uncontrolled search path element vulnerability in CLUSTERPRO X 5.0 and EXPRESSCLUSTER X 5.0 for Windows, allowing a remote attacker to overwrite files.
What software versions are affected by CVE-2022-34825?
CVE-2022-34825 affects CLUSTERPRO X 5.0 and EXPRESSCLUSTER X 5.0 for Windows, including SingleServerSafe versions.
What is the severity of CVE-2022-34825?
CVE-2022-34825 has a severity rating of 9.8 (Critical).
How can an attacker exploit CVE-2022-34825?
An attacker can exploit CVE-2022-34825 by sending a specially crafted request to overwrite files on the affected system.
Is there a fix available for CVE-2022-34825?
Yes, it is recommended to update to a fixed version of CLUSTERPRO X 5.0 and EXPRESSCLUSTER X 5.0 for Windows to mitigate the vulnerability.