CVE Feed

    Dashboard / CVE / CVE-2022-37122

    CVE-2022-37122

    Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

    Published:Aug 31, 2022
    Last Modified:Nov 21, 2024
    EPS:Aug 31, 2022
    EPSS Score:0.14211
    CVSS Score:7.5

    Affected Products

    Vendor
    Carel
    Product
    Applica
    Vendor
    Carel
    Product
    Pcoweb Card
    Vendor
    Carel
    Product
    Pcoweb Card Firmware
    Vendor
    Carel
    Product
    Pcoweb Hvac Bacnet Gateway

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High