Vulnerability Description
Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file paths under the /js/ path. Attackers can exploit the issue by sending requests like /js/../../../../.../etc/passwd%00.jpg (null-byte appended traversal) to access critical files such as /etc/passwd and /etc/shadow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kyocera | Command Center Rx | ecosys_m2035dn |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/50738Exploit
- https://www.kyoceradocumentsolutions.com/asia/en/products/business-application/cProduct
- https://www.vulncheck.com/advisories/kyocera-command-center-rx-ecosys-mdn-directThird Party Advisory
- https://www.exploit-db.com/exploits/50738Exploit
FAQ
What is CVE-2022-50932?
CVE-2022-50932 is a vulnerability with a CVSS score of 7.5 (HIGH). Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file paths under the /js/ pat...
How severe is CVE-2022-50932?
CVE-2022-50932 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50932?
Check the references section above for vendor advisories and patch information. Affected products include: Kyocera Command Center Rx.