Vulnerability Details CVE-2022-47188
There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing a symlink to /etc/shadow, allowing him to obtain the content of this path.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.2%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2022-47188
-
cpe:2.3:h:generex:cs141:-
-
cpe:2.3:o:generex:cs141_firmware:-
-
cpe:2.3:o:generex:cs141_firmware:1.90
-
cpe:2.3:o:generex:cs141_firmware:2.00
-
cpe:2.3:o:generex:cs141_firmware:2.02
-
cpe:2.3:o:generex:cs141_firmware:2.04