9.8
CVSSv3

CVE-2022-47526

Published: 31/05/2023 Updated: 07/06/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of this issue does not require user interaction.

Vulnerable Product Search on Vulmon Subscribe to Product

fox-it fox_datadiode_firmware 3.4.3