HIGH
PILZ: PASvisu and PMI affected by ZipSlip
Published Nov 24, 2022
7.5
HIGHCVSS 3.1
EPSS 0.92%
Description
A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<1.12.0
- Version
-
- Version 1.0.0StatusaffectedConstraints<=1.3.58
- Version 1.0.0StatusaffectedConstraints<1.6.102
- Version 1.0.0StatusaffectedConstraints<2.2.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 2
AND
- ≤ 1.3.58
Configuration 3
AND
- ≤ 1.3.58
Configuration 4
AND
- < 2.2.0
Configuration 5
AND
- < 2.2.0
Configuration 6
AND
- < 1.6.102
Configuration 7
AND
- < 1.6.102
Configuration 8
AND
- < 1.6.102
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://cert.vde.com/en/advisories/VDE-2022-033/ MitigationThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-033/ | MitigationThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERTVDE
Published Nov 24, 2022
Updated Apr 24, 2025
Reserved Sep 19, 2022
Link CVE-2022-40977
CISA Vulnrichment
Updated Apr 24, 2025