VYPR
High severity7.5NVD Advisory· Published Aug 31, 2022· Updated Jun 17, 2026

CVE-2022-37122

CVE-2022-37122

Description

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Carel/Applica2 versions
    cpe:2.3:a:carel:applica:16_13020200:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:carel:applica:16_13020200:*:*:*:*:*:*:*
    • cpe:2.3:a:carel:applica:2.154a:*:*:*:*:*:*:*
  • cpe:2.3:a:carel:pcoweb_hvac_bacnet_gateway:2.1.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:carel:pcoweb_hvac_bacnet_gateway:2.1.0:*:*:*:*:*:*:*
    • (no CPE)range: 2.1.0, A2.1.0 - B2.1.0, 2.15.4A Software v16 13020200
  • cpe:2.3:o:carel:pcoweb_card_firmware:*:*:*:*:*:*:*:*
    Range: >=a2.1.0,<=b.2.1.0
  • Carel/pCOWeb HVAC BACnet Gatewaydescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.