CVE-2022-0902
high · 8.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node.
8.1
CVSS
16.5%
EPSS (exploit prob.)
97th
EPSS percentile
2022-07-21
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22CWE-77
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| abb | rmc-100_firmware | < 2105457-037 |
| abb | rmc-100 | all versions |
| abb | rmc-100-lite_firmware | < 2106229-011 |
| abb | rmc-100-lite | all versions |
| abb | xio_firmware | < 2106198-008 |
| abb | xio | all versions |
| abb | xfcg5_firmware | < 2105805-016 |
| abb | xfcg5 | all versions |
| abb | xrcg5_firmware | < 2105864-016 |
| abb | xrcg5 | all versions |
| abb | uflog5_firmware | < 2105298-024 |
| abb | uflog5 | all versions |
| abb | udc_firmware | < 2106177-007 |
| abb | udc | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-0902