CVE-2021-22646

The ipk package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
icscertCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
ovarrotwinsoft
𝑥
< 12.4
ovarrotbox_lt2-530_firmware
𝑥
< 1.46
ovarrotbox_lt2-532_firmware
𝑥
< 1.46
ovarrotbox_lt2-540_firmware
𝑥
< 1.46
ovarrotbox_ms-cpu32_firmware
𝑥
< 1.46
ovarrotbox_ms-cpu32-s2_firmware
𝑥
< 1.46
ovarrotbox_rm2_firmware
𝑥
< 1.46
ovarrotbox_tg2_firmware
𝑥
< 1.46
𝑥
= Vulnerable software versions