CVE-2022-4779

StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. StreamX applications using StreamView HTML component with the public web server feature activated are affected.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elvexys:streamx:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5
References () https://elvexys.com/products/xpg-gateway-rtu-protocol-converter/streamx-release-notes/ - Release Notes, Vendor Advisory () https://elvexys.com/products/xpg-gateway-rtu-protocol-converter/streamx-release-notes/ - Release Notes, Vendor Advisory

07 Nov 2023, 03:58

Type Values Removed Values Added
Summary StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. StreamX applications using StreamView HTML component with the public web server feature activated are affected. StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. StreamX applications using StreamView HTML component with the public web server feature activated are affected.

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-287 CWE-22

Information

Published : 2022-12-29 00:15

Updated : 2025-04-10 21:15


NVD link : CVE-2022-4779

Mitre link : CVE-2022-4779

CVE.ORG link : CVE-2022-4779


JSON object : View

Products Affected

elvexys

  • streamx
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')