CVE-2022-4636: Path Traversal
Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-4636?
CVE-2022-4636 refers to a vulnerability in Black Box KVM Firmware version 3.4.31307 on specific models, which allows for path traversal and potential theft of user credentials and sensitive information through local file inclusion.
Which software versions are affected by CVE-2022-4636?
Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T are affected.
How severe is CVE-2022-4636?
CVE-2022-4636 has a severity rating of 7.5 (high).
How can an attacker exploit CVE-2022-4636?
An attacker can exploit CVE-2022-4636 by performing path traversal and conducting local file inclusion attacks to steal user credentials and sensitive information.
Is there a fix available for CVE-2022-4636?
To fix CVE-2022-4636, it is recommended to update the affected Black Box KVM Firmware to a secure version that addresses the vulnerability.