CVE-2022-38129: Path Traversal
Published Aug 10, 2022
·Updated
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.
Affected Software
1 affected component
keysight Sensor Management Server=2.4.0
Event History
Aug 10, 2022
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-38129?
CVE-2022-38129 is classified as a critical severity vulnerability.
2
How do I fix CVE-2022-38129?
To fix CVE-2022-38129, update your Keysight Sensor Management Server to version 2.4.1 or later.
3
What types of attacks can exploit CVE-2022-38129?
CVE-2022-38129 can be exploited by unauthenticated remote attackers to upload arbitrary files.
4
Which version of Keysight Sensor Management Server is affected by CVE-2022-38129?
CVE-2022-38129 affects Keysight Sensor Management Server version 2.4.0.
5
Is authentication required to exploit CVE-2022-38129?
No, authentication is not required to exploit CVE-2022-38129.