Vulnerability Description
Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent to /fm-data.lua.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Algosolutions | 8373 Ip Zone Paging Adapter Firmware | 1.7.6 |
| Algosolutions | 8373 Ip Zone Paging Adapter | - |
Related Weaknesses (CWE)
References
- https://n0ur5sec.medium.com/achievement-unlocked-cve-2022-31395-33299f32cc00ExploitThird Party Advisory
- https://n0ur5sec.medium.com/achievement-unlocked-cve-2022-31395-33299f32cc00ExploitThird Party Advisory
FAQ
What is CVE-2022-31395?
CVE-2022-31395 is a vulnerability with a CVSS score of 8.8 (HIGH). Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent to /fm-data.lua.
How severe is CVE-2022-31395?
CVE-2022-31395 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31395?
Check the references section above for vendor advisories and patch information. Affected products include: Algosolutions 8373 Ip Zone Paging Adapter Firmware, Algosolutions 8373 Ip Zone Paging Adapter.