CVE-2022-46306

HIGH

ChangingTec ServiSign - Path Traversal

Title source: llm
STIX 2.1

Description

ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers the component to load malicious DLL files under arbitrary file path and allows the attacker to perform arbitrary system operation and disrupt of service.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0092
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
changingtec/servisign
Published Jan 03, 2023
Tracked Since Feb 18, 2026