CVE Vulnerabilities

CVE-2022-38715

Active Debug Code

Published: Jan 26, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

Weakness

The product is released with debugging code still enabled or active.

Affected Software

NameVendorStart VersionEnd Version
Quartz-gold_firmwareSirettag5.0.1.5-210720-141020 (including)g5.0.1.5-210720-141020 (including)

Potential Mitigations

References