SmartICS
by Elcomplus
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2140 | Hig | 0.57 | 8.8 | 0.01 | Jun 27, 2022 | Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters. | ||
| CVE-2022-2088 | Med | 0.44 | 6.8 | 0.01 | Jun 27, 2022 | An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartICS v2.3.4.0. | ||
| CVE-2022-2106 | Low | 0.25 | 3.8 | 0.01 | Jun 27, 2022 | Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files. |
- risk 0.57cvss 8.8epss 0.01
Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters.
- risk 0.44cvss 6.8epss 0.01
An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartICS v2.3.4.0.
- risk 0.25cvss 3.8epss 0.01
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files.