Vulnerability Description
Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Systematicalpha | Systematic Fix Adapter Firmware | 2.4.0.25 |
| Systematicalpha | Systematic Fix Adapter | - |
Related Weaknesses (CWE)
References
- http://systematicalpha.com/companyProduct
- http://systematicalpha.com/trading-programs/systematic-alpha-fx-master-fundPermissions RequiredVendor Advisory
- https://github.com/jet-pentest/CVE-2022-39838ExploitThird Party Advisory
- http://systematicalpha.com/companyProduct
- http://systematicalpha.com/trading-programs/systematic-alpha-fx-master-fundPermissions RequiredVendor Advisory
- https://github.com/jet-pentest/CVE-2022-39838ExploitThird Party Advisory
FAQ
What is CVE-2022-39838?
CVE-2022-39838 is a vulnerability with a CVSS score of 8.6 (HIGH). Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.
How severe is CVE-2022-39838?
CVE-2022-39838 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-39838?
Check the references section above for vendor advisories and patch information. Affected products include: Systematicalpha Systematic Fix Adapter Firmware, Systematicalpha Systematic Fix Adapter.