High severity7.5NVD Advisory· Published Jan 10, 2023· Updated Jun 17, 2026
CVE-2022-4636
CVE-2022-4636
Description
Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:o:blackbox:acr1000a-r-r2_firmware:3.4.31307:*:*:*:*:*:*:*
- cpe:2.3:o:blackbox:acr1000a-t-r2_firmware:3.4.31307:*:*:*:*:*:*:*
- cpe:2.3:o:blackbox:acr1002a-r_firmware:3.4.31307:*:*:*:*:*:*:*
- cpe:2.3:o:blackbox:acr1002a-t_firmware:3.4.31307:*:*:*:*:*:*:*
- cpe:2.3:o:blackbox:acr1020a-t_firmware:3.4.31307:*:*:*:*:*:*:*
- Range: 3.4.31307
3.4.31307+ 1 more
- (no CPE)range: 3.4.31307
- (no CPE)range: 3.4.31307
- Range: 3.4.31307
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsa-23-010-01nvdPatchThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.