Unrated severityNVD Advisory· Published Nov 24, 2022· Updated Apr 25, 2025
PILZ: Multiple products affected by ZipSlip
CVE-2022-40976
Description
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
Affected products
2- Range: 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.