VYPR
Unrated severityNVD Advisory· Published Nov 24, 2022· Updated Apr 25, 2025

PILZ: Multiple products affected by ZipSlip

CVE-2022-40976

Description

A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.