A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Pilz
Subscribe
|
Pasvisu
Subscribe
Pmi V507
Subscribe
Pmi V507 Firmware
Subscribe
Pmi V512
Subscribe
Pmi V512 Firmware
Subscribe
Pmi V704e
Subscribe
Pmi V704e Firmware
Subscribe
Pmi V707e
Subscribe
Pmi V707e Firmware
Subscribe
Pmi V807
Subscribe
Pmi V807 Firmware
Subscribe
Pmi V812
Subscribe
Pmi V812 Firmware
Subscribe
Pmi V815
Subscribe
Pmi V815 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-44223 | A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-033/ |
|
History
Thu, 24 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-04-24T19:47:34.589Z
Reserved: 2022-09-19T14:13:38.097Z
Link: CVE-2022-40977
Updated: 2024-08-03T12:28:42.959Z
Status : Modified
Published: 2022-11-24T10:15:11.013
Modified: 2024-11-21T07:22:20.607
Link: CVE-2022-40977
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD