CVE-2022-4636
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
10/01/2023
Last modified:
07/11/2023
Description
Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.<br />
<br />
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:blackbox:acr1000a-r-r2_firmware:3.4.31307:*:*:*:*:*:*:* | ||
| cpe:2.3:h:blackbox:acr1000a-r-r2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:blackbox:acr1000a-t-r2_firmware:3.4.31307:*:*:*:*:*:*:* | ||
| cpe:2.3:h:blackbox:acr1000a-t-r2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:blackbox:acr1002a-r_firmware:3.4.31307:*:*:*:*:*:*:* | ||
| cpe:2.3:h:blackbox:acr1002a-r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:blackbox:acr1002a-t_firmware:3.4.31307:*:*:*:*:*:*:* | ||
| cpe:2.3:h:blackbox:acr1002a-t:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:blackbox:acr1020a-t_firmware:3.4.31307:*:*:*:*:*:*:* | ||
| cpe:2.3:h:blackbox:acr1020a-t:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



