CVE-2022-40976: PILZ: Multiple products affected by ZipSlip
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40976?
CVE-2022-40976 is a path traversal vulnerability in multiple Pilz products that allows an unauthenticated local attacker to trigger arbitrary file writes ('zip-slip').
How does CVE-2022-40976 affect Pilz Pas 4000?
CVE-2022-40976 affects Pilz Pas 4000 versions up to and excluding 1.25.0 and can be exploited by an unauthenticated local attacker.
Is Pilz Pss 4000 affected by CVE-2022-40976?
No, Pilz Pss 4000 is not affected by CVE-2022-40976.
What versions of Pliz Pascal are affected by CVE-2022-40976?
CVE-2022-40976 affects Pliz Pascal versions up to and including 1.9.1.
How can the Pilz Pnozmulti Configurator be affected by CVE-2022-40976?
CVE-2022-40976 affects Pliz Pnozmulti Configurator versions up to and excluding 10.14.4 and 11.2.0.