CVE Vulnerabilities

CVE-2022-36302

Improper Restriction of Names for Files and Other Resources

Published: Aug 01, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information.

Weakness

The product constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name.

Affected Software

Name Vendor Start Version End Version
Bf-os Bosch 3.00 (including) 3.83 (including)

Potential Mitigations

References