CRITICAL🇵🇱 Wersja polska

CVE-2022-43483

CVSS 9.1v3.1pub. 2023-01-18upd. 2024-11-21

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to the monitor services of the software. This could allow a remote attacker to access sensitive functions of the application and execute arbitrary system commands.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Sewio Real Time Location System Studio

    APP
    Sewio
    2.0.0 – 2.6.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-47911CRITICAL9.1PL ✓same product

Command Injection w Sewio RTLS Studio — wykonanie dowolnych poleceń systemowych

CVE-2022-41989CRITICAL9.0PL ✓same product

Przepełnienie bufora w Sewio RTLS Studio umożliwiające RCE lub DoS

CVE-2022-45444CRITICAL10.0PL ✓same product

Sewio RTLS Studio — zakodowane na stałe hasła umożliwiające dostęp do bazy danych

CVE-2022-47395HIGH8.1same product

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable ...

CVE-2022-45127HIGH8.1same product

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable ...