First published: Thu Jan 26 2023(Updated: )
A directory traversal vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siretta Quartz-gold Firmware | =g5.0.1.5-210720-141020 | |
Siretta QUARTZ-GOLD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40701 is classified as a critical vulnerability due to its potential for arbitrary file deletion.
To patch CVE-2022-40701, upgrade the Siretta QUARTZ-GOLD firmware to a version that includes the security fix.
CVE-2022-40701 specifically affects Siretta QUARTZ-GOLD firmware version g5.0.1.5-210720-141020.
CVE-2022-40701 enables attackers to perform a directory traversal attack leading to arbitrary file deletion.
You can determine if your system is vulnerable to CVE-2022-40701 by checking if your Siretta QUARTZ-GOLD firmware is version g5.0.1.5-210720-141020.