HIGH · 7.5

CVE-2022-37122

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input pa...

Vulnerability Description

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CarelPcoweb Card Firmware>= a2.1.0, <= b.2.1.0
CarelPcoweb Card-
CarelApplica2.154a
CarelPcoweb Hvac Bacnet Gateway2.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-37122?

CVE-2022-37122 is a vulnerability with a CVSS score of 7.5 (HIGH). Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input pa...

How severe is CVE-2022-37122?

CVE-2022-37122 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-37122?

Check the references section above for vendor advisories and patch information. Affected products include: Carel Pcoweb Card Firmware, Carel Pcoweb Card, Carel Applica, Carel Pcoweb Hvac Bacnet Gateway.