CVE-2022-26233
Last modified
CVE-2022-26233 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.. EPSS estimates a 15.03% chance of exploitation in the next 30 days.
Description
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Barco | Control Room Management Suite | <= 2.9 |
References
- http://packetstormsecurity.com/files/166577/Barco-Control-Room-Management-Suite-Directory-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Apr/0Exploit, Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/166577/Barco-Control-Room-Management-Suite-Directory-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Apr/0Exploit, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-26233?
How severe is CVE-2022-26233?
How do I fix CVE-2022-26233?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-26211Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B2…9.8
- CVE-2022-26212Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B2…9.8
- CVE-2022-26213Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discover…9.8
- CVE-2022-26214Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B2…9.8
- CVE-2022-2622Insufficient validation of untrusted input in Safe Browsing …6.5
- CVE-2022-2623Use after free in Offline in Google Chrome on Android prior …8.8
- CVE-2022-26235A vulnerability was discovered in the Remisol Advance v2.0.1…7.8
- CVE-2022-26236The default privileges for the running service Normand Remis…5.5
- CVE-2022-26237The default privileges for the running service Normand Viewe…5.5
- CVE-2022-26238The default privileges for the running service Normand Servi…5.5
- CVE-2022-26239The default privileges for the running service Normand Licen…5.5
- CVE-2022-2624Heap buffer overflow in PDF in Google Chrome prior to 104.0.…8.8
Are you affected by CVE-2022-26233?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
