Vulnerability Description
Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blackbox | Acr1000A-R-R2 Firmware | 3.4.31307 |
| Blackbox | Acr1000A-R-R2 | - |
| Blackbox | Acr1000A-T-R2 Firmware | 3.4.31307 |
| Blackbox | Acr1000A-T-R2 | - |
| Blackbox | Acr1002A-R Firmware | 3.4.31307 |
| Blackbox | Acr1002A-R | - |
| Blackbox | Acr1002A-T Firmware | 3.4.31307 |
| Blackbox | Acr1002A-T | - |
| Blackbox | Acr1020A-T Firmware | 3.4.31307 |
| Blackbox | Acr1020A-T | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-010-01PatchThird Party AdvisoryUS Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-23-010-01PatchThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2022-4636?
CVE-2022-4636 is a vulnerability with a CVSS score of 7.5 (HIGH). Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user crede...
How severe is CVE-2022-4636?
CVE-2022-4636 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4636?
Check the references section above for vendor advisories and patch information. Affected products include: Blackbox Acr1000A-R-R2 Firmware, Blackbox Acr1000A-R-R2, Blackbox Acr1000A-T-R2 Firmware, Blackbox Acr1000A-T-R2, Blackbox Acr1002A-R Firmware.