Vulnerability Description
A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pilz | Pasvisu | < 1.12.0 |
| Pilz | Pmi V507 Firmware | <= 1.3.58 |
| Pilz | Pmi V507 | - |
| Pilz | Pmi V512 Firmware | <= 1.3.58 |
| Pilz | Pmi V512 | - |
| Pilz | Pmi V704E Firmware | < 2.2.0 |
| Pilz | Pmi V704E | - |
| Pilz | Pmi V707E Firmware | < 2.2.0 |
| Pilz | Pmi V707E | - |
| Pilz | Pmi V807 Firmware | < 1.6.102 |
| Pilz | Pmi V807 | - |
| Pilz | Pmi V812 Firmware | < 1.6.102 |
| Pilz | Pmi V812 | - |
| Pilz | Pmi V815 Firmware | < 1.6.102 |
| Pilz | Pmi V815 | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en/advisories/VDE-2022-033/MitigationThird Party Advisory
- https://cert.vde.com/en/advisories/VDE-2022-033/MitigationThird Party Advisory
FAQ
What is CVE-2022-40977?
CVE-2022-40977 is a vulnerability with a CVSS score of 7.5 (HIGH). A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes...
How severe is CVE-2022-40977?
CVE-2022-40977 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40977?
Check the references section above for vendor advisories and patch information. Affected products include: Pilz Pasvisu, Pilz Pmi V507 Firmware, Pilz Pmi V507, Pilz Pmi V512 Firmware, Pilz Pmi V512.