CVE-2022-40977: PILZ: PASvisu and PMI affected by ZipSlip
A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pilz PASvisu Serverto a version that resolves this vulnerability.Fixed in 1.12.0
Event History
Frequently Asked Questions
What is CVE-2022-40977?
CVE-2022-40977 is a path traversal vulnerability in Pilz PASvisu Server before version 1.12.0.
How does the CVE-2022-40977 vulnerability work?
The CVE-2022-40977 vulnerability allows an unauthenticated remote attacker to use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip').
What is the severity of CVE-2022-40977?
CVE-2022-40977 has a severity rating of high (7.5).
Which software versions are affected by CVE-2022-40977?
Pilz PASvisu Server version before 1.12.0 is affected by CVE-2022-40977.
How can I fix CVE-2022-40977?
The recommended fix for CVE-2022-40977 is to upgrade Pilz PASvisu Server to version 1.12.0 or later.