CVE-2022-46304

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
03/01/2023
Last modified:
09/01/2023

Description

ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers command injection and allows the attacker to execute arbitrary system command to perform arbitrary system operation or disrupt service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:changingtec:servisign:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools