CVE-2022-39838

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
05/09/2022
Last modified:
09/09/2022

Description

Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:systematicalpha:systematic_fix_adapter_firmware:2.4.0.25:*:*:*:*:*:*:*
cpe:2.3:h:systematicalpha:systematic_fix_adapter:-:*:*:*:*:*:*:*