The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficiently sanitized. The vendor's ID is BSECV-2022-21.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-11-25T00:00:00

Updated: 2022-11-30T00:00:00

Reserved: 2022-09-08T00:00:00


Link: CVE-2022-40282

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-11-25T05:15:13.010

Modified: 2023-08-08T14:22:24.967


Link: CVE-2022-40282

JSON object: View

cve-icon Redhat Information

No data.