CVE-2023-22282

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
11/04/2023
Last modified:
11/02/2025

Description

WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elecom:wab-mat:*:*:*:*:*:*:*:* 5.0.2.2 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*