← Back

CVE-2022-0902

nvd nist
Published: Jul 21, 2022Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node.

Affected (7)

7 products
Rmc 100 Firmware
Rmc 100 Lite Firmware
Xio Firmware
Xfcg5 Firmware
Xrcg5 Firmware
Uflog5 Firmware
Udc Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2105457-037
Running on/withPlatform Versions
Abb
Rmc 100
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2106229-011
Running on/withPlatform Versions
Abb
Rmc 100 Lite
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2106198-008
Running on/withPlatform Versions
Abb
Xio
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2105805-016
Running on/withPlatform Versions
Abb
Xfcg5
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2105864-016
Running on/withPlatform Versions
Abb
Xrcg5
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2105298-024
Running on/withPlatform Versions
Abb
Uflog5
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2106177-007
Running on/withPlatform Versions
Abb
Udc
All versions

Timeline

No history available yet.