CVE-2022-0902
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node.
Published:Jul 21, 2022
Last Modified:Nov 21, 2024
EPS:Jul 21, 2022
EPSS Score:0.23792
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Abb
Product
Rmc-100
Abb
Rmc-100
Vendor
Abb
Product
Rmc-100-lite
Abb
Rmc-100-lite
Vendor
Abb
Product
Rmc-100-lite Firmware
Abb
Rmc-100-lite Firmware
Vendor
Abb
Product
Rmc-100 Firmware
Abb
Rmc-100 Firmware
Vendor
Abb
Product
Udc
Abb
Udc
Vendor
Abb
Product
Udc Firmware
Abb
Udc Firmware
Vendor
Abb
Product
Uflog5
Abb
Uflog5
Vendor
Abb
Product
Uflog5 Firmware
Abb
Uflog5 Firmware
Vendor
Abb
Product
Xfcg5
Abb
Xfcg5
Vendor
Abb
Product
Xfcg5 Firmware
Abb
Xfcg5 Firmware
Vendor
Abb
Product
Xio
Abb
Xio
Vendor
Abb
Product
Xio Firmware
Abb
Xio Firmware
Vendor
Abb
Product
Xrcg5
Abb
Xrcg5
Vendor
Abb
Product
Xrcg5 Firmware
Abb
Xrcg5 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
