An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application. This could lead to uploading python files which can be later executed.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-216-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-08-10 13:15
Updated : 2022-08-16 04:57
NVD link : CVE-2022-2634
Mitre link : CVE-2022-2634
JSON object : View
CWE
CWE-250
Execution with Unnecessary Privileges
Products Affected
digi
- connectport_x2d
- connectport_x2d_firmware