• CVE-2022-37122 | Carel pCOWeb HVAC BACnet Gateway GET Parameter logdow

    From Security Bot@2:467/888.88 to All on Sun Jan 8 00:10:06 2023


    Title: CVE-2022-37122 | Carel pCOWeb HVAC BACnet Gateway GET Parameter logdownload.cgi file pathname traversal (ID 167684)
    Description: A vulnerability was found in Carel pCOWeb HVAC BACnet Gateway. It has been classified as critical. Affected is an unknown function of the file logdownload.cgi of the component GET Parameter Handler. The manipulation of the argument file leads to pathname traversal.
    Link: https://vuldb.com/?id.207654
    Thu, 01 Sep 2022 10:32:11 +0200


    --- The information is for informational purposes only.
    * Origin: Read us with http://winpoint.org/ (2:467/888.88)