PT-2023-15101 · Vocera · Vocera Voice Server+2

CVE-2022-46900

·

Publicado

2023-07-25

·

Atualizado

2024-10-29

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vocera Report Server and Voice Server versions 5.x through 5.8
Description An issue was discovered in the software, allowing Path Traversal in the Task Exec filename. The Vocera Report Console contains various jobs executed on the server at specified intervals, such as backup. An authenticated user can modify these entries, setting the executable path and parameters.
Recommendations For versions 5.x through 5.8, consider restricting access to the Task Exec filename to prevent Path Traversal attacks. As a temporary workaround, limit the ability of authenticated users to modify job entries in the Vocera Report Console. Restrict the setting of executable paths and parameters to minimize the risk of exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-46900

Produtos afetados

Vocera Report Console
Vocera Report Server
Vocera Voice Server