CVE-2022-29509
Directory traversal vulnerability in T&D Data Server (Japanese Edition) Ver.2.22 and earlier, T&D Data Server (English Edition) Ver.2.30 and earlier, THERMO RECORDER DATA SERVER (Japanese Edition) Ver.2.13 and earlier, and THERMO RECORDER DATA SERVER…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Directory traversal vulnerability in T&D Data Server (Japanese Edition) Ver.2.22 and earlier, T&D Data Server (English Edition) Ver.2.30 and earlier, THERMO RECORDER DATA SERVER (Japanese Edition) Ver.2.13 and earlier, and THERMO RECORDER DATA SERVER (English Edition) Ver.2.13 and earlier allows a remote attacker to view an arbitrary file on the server via unspecified vectors.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.40% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- tandd/t\&d server · tandd/thermo recorder data server firmware
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN28659051/index.htmlThird Party Advisory, VDB Entry
- https://tandd.com/news/detail.html?id=696Vendor Advisory
- https://www.tandd.co.jp/news/detail.html?id=522Vendor Advisory
- https://jvn.jp/en/jp/JVN28659051/index.htmlThird Party Advisory, VDB Entry
- https://tandd.com/news/detail.html?id=696Vendor Advisory
- https://www.tandd.co.jp/news/detail.html?id=522Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.