← Back

CVE-2022-2102

nvd nist
Published: Jun 24, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.

Affected (3)

1 product
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Secheron
From 1.23.0 to 1.23.21
From 1.24.0 to 1.24.8
From 1.25.0 to 1.25.3
Running on/withPlatform Versions
Secheron
Sepcos Control And Protection Relay
All versions

References (2)

Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource

Timeline

No history available yet.