Critical severity9.4NVD Advisory· Published Jun 24, 2022· Updated Jun 17, 2026
CVE-2022-2102
CVE-2022-2102
Description
Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.
Affected products
1- Secheron/SEPCOS Control and Protection Relay firmware packagev5Range: All versions
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-174-03nvdMitigationThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.