CVE-2022-41772: Path Traversal
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41772?
CVE-2022-41772 is a vulnerability in Delta Electronics InfraSuite Device Master versions 00.00.01a and prior that mishandles .ZIP archives containing characters used in path traversal, which could result in remote code execution.
How severe is CVE-2022-41772?
The severity of CVE-2022-41772 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2022-41772?
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior are affected by CVE-2022-41772.
How can the path traversal vulnerability in CVE-2022-41772 be exploited?
The path traversal vulnerability in CVE-2022-41772 can be exploited by manipulating .ZIP archives containing specific characters.
Is there a fix available for CVE-2022-41772?
It is recommended to update Delta Electronics InfraSuite Device Master to version 00.00.02a or later to fix the vulnerability in CVE-2022-41772.