VYPR

Fox Datadiode Firmware

by Fox It

CVEs (2)

  • CVE-2022-47526CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of…

  • CVE-2022-47525HigMay 31, 2023
    risk 0.49cvss 7.5epss 0.01

    Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a Divide-by-Zero vulnerability in the packet parser. A remote attacker could leverage this vulnerability to cause a denial-of-service. Exploitation of this issue does not require user interaction.