VYPR
Unrated severityNVD Advisory· Published Jul 21, 2022· Updated Sep 17, 2024

ABB Flow Computer and Remote Controllers Path Traversal Vulnerability in Totalflow TCP protocol can lead to root access

CVE-2022-0902

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node.

Affected products

8

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.