CVE-2022-40976
24.11.2022, 10:15
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.| Vendor | Product | Version |
|---|---|---|
| pilz | pas_4000 | 𝑥 < 1.25.0 |
| pliz | pascal | 𝑥 ≤ 1.9.1 |
| pliz | pasconnect | 𝑥 < 1.4.0 |
| pliz | pasmotion | 𝑥 < 1.4.1 |
| pliz | pnozmulti_configurator | 𝑥 < 10.14.4 |
| pliz | pnozmulti_configurator | 𝑥 < 11.2.0 |
𝑥
= Vulnerable software versions