← Back

CVE-2022-46900

nvd nist
Published: Jul 25, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Exec filename. The Vocera Report Console contains various jobs that are executed on the server at specified intervals, e.g., backup, etc. An authenticated user has the ability to modify these entries and set the executable path and parameters.

Affected (2)

2 products
Report Server
Voice Server
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
From 5.0.0 to 5.8.0.135
From 5.0.0 to 5.8.0.135

Timeline

No history available yet.