CVE-2022-2634
Summary
| CVE | CVE-2022-2634 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-10 20:15:00 UTC |
| Updated | 2022-08-16 11:57:00 UTC |
| Description | An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application. This could lead to uploading python files which can be later executed. |
Risk And Classification
Problem Types: CWE-250
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Digi | Connectport X2d | - | All | All | All |
| Operating System | Digi | Connectport X2d Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Digi ConnectPort X2D | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Aarón Flecha of S21sec reported this vulnerability to CISA.
There are currently no legacy QID mappings associated with this CVE.