CVE-2022-40976
24.11.2022, 10:15
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
Vendor | Product | Version |
---|---|---|
pilz | pas_4000 | 𝑥 < 1.25.0 |
pliz | pascal | 𝑥 ≤ 1.9.1 |
pliz | pasconnect | 𝑥 < 1.4.0 |
pliz | pasmotion | 𝑥 < 1.4.1 |
pliz | pnozmulti_configurator | 𝑥 < 10.14.4 |
pliz | pnozmulti_configurator | 𝑥 < 11.2.0 |
𝑥
= Vulnerable software versions