CVE-2022-28223
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
30/03/2022
Last modified:
07/11/2023
Description
Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:h:tekon:kio:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tekon:kio_firmware:*:*:*:*:*:*:*:* | 2022-03-30 (including) | |
cpe:2.3:h:tekon:kio-1m:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tekon:kio-1m_firmware:*:*:*:*:*:*:*:* | 2022-03-30 (including) | |
cpe:2.3:h:tekon:kio-2mrs:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tekon:kio-2mrs_firmware:*:*:*:*:*:*:*:* | 2022-03-30 (including) | |
cpe:2.3:h:tekon:kio-2m:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tekon:kio-2m_firmware:*:*:*:*:*:*:*:* | 2022-03-30 (including) | |
cpe:2.3:h:tekon:kio-2ms:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tekon:kio-2ms_firmware:*:*:*:*:*:*:*:* | 2022-03-30 (including) | |
cpe:2.3:h:tekon:kio-2md:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tekon:kio-2md_firmware:*:*:*:*:*:*:*:* | 2022-03-30 (including) | |
cpe:2.3:h:tekon:kio-8\(4\):-:*:*:*:*:*:*:* | ||
cpe:2.3:o:tekon:kio-8\(4\)_firmware:*:*:*:*:*:*:*:* | 2022-03-30 (including) | |
cpe:2.3:h:tekon:kio-8\(4\)l:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page