// For flags

CVE-2022-31483

Arbitrary file write via authenticated OSDP file upload

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.271. This allows a malicious actor to overwrite sensitive system files and install a startup service to gain remote access to the underlaying Linux operating system with root privileges.

Un atacante autenticado puede cargar un archivo con un nombre de archivo que incluya ".." y "/" para lograr la capacidad de cargar el archivo deseado en cualquier lugar del sistema de archivos. Esta vulnerabilidad afecta a los productos basados en los controladores inteligentes HID Mercury LP1501, LP1502, LP2500, LP4502 y EP4502 que contienen versiones de firmware anteriores a 1.271. Esto permite a un actor malicioso sobrescribir archivos confidenciales del sistema e instalar un servicio de inicio para conseguir acceso remoto al sistema operativo Linux subyacente con privilegios de root

*Credits: Sam Quinn @eAyeP and Steve Povolny @spovolny from Trellix Threat Labs
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-05-23 CVE Reserved
  • 2022-06-06 CVE Published
  • 2023-12-28 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hidglobal
Search vendor "Hidglobal"
Lp1501 Firmware
Search vendor "Hidglobal" for product "Lp1501 Firmware"
< 1.271
Search vendor "Hidglobal" for product "Lp1501 Firmware" and version " < 1.271"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Lp1501
Search vendor "Hidglobal" for product "Lp1501"
--
Safe
Hidglobal
Search vendor "Hidglobal"
Lp1502 Firmware
Search vendor "Hidglobal" for product "Lp1502 Firmware"
< 1.271
Search vendor "Hidglobal" for product "Lp1502 Firmware" and version " < 1.271"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Lp1502
Search vendor "Hidglobal" for product "Lp1502"
--
Safe
Hidglobal
Search vendor "Hidglobal"
Lp2500 Firmware
Search vendor "Hidglobal" for product "Lp2500 Firmware"
< 1.271
Search vendor "Hidglobal" for product "Lp2500 Firmware" and version " < 1.271"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Lp2500
Search vendor "Hidglobal" for product "Lp2500"
--
Safe
Hidglobal
Search vendor "Hidglobal"
Lp4502 Firmware
Search vendor "Hidglobal" for product "Lp4502 Firmware"
< 1.271
Search vendor "Hidglobal" for product "Lp4502 Firmware" and version " < 1.271"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Lp4502
Search vendor "Hidglobal" for product "Lp4502"
--
Safe
Hidglobal
Search vendor "Hidglobal"
Ep4502 Firmware
Search vendor "Hidglobal" for product "Ep4502 Firmware"
< 1.271
Search vendor "Hidglobal" for product "Ep4502 Firmware" and version " < 1.271"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Ep4502
Search vendor "Hidglobal" for product "Ep4502"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-4420 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-4420 Firmware"
< 1.271
Search vendor "Carrier" for product "Lenels2 Lnl-4420 Firmware" and version " < 1.271"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-4420
Search vendor "Carrier" for product "Lenels2 Lnl-4420"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-x2210 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-x2210 Firmware"
< 1.271
Search vendor "Carrier" for product "Lenels2 Lnl-x2210 Firmware" and version " < 1.271"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-x2210
Search vendor "Carrier" for product "Lenels2 Lnl-x2210"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-x2220 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-x2220 Firmware"
< 1.271
Search vendor "Carrier" for product "Lenels2 Lnl-x2220 Firmware" and version " < 1.271"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-x2220
Search vendor "Carrier" for product "Lenels2 Lnl-x2220"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-x3300 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-x3300 Firmware"
< 1.271
Search vendor "Carrier" for product "Lenels2 Lnl-x3300 Firmware" and version " < 1.271"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-x3300
Search vendor "Carrier" for product "Lenels2 Lnl-x3300"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-x4420 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-x4420 Firmware"
< 1.271
Search vendor "Carrier" for product "Lenels2 Lnl-x4420 Firmware" and version " < 1.271"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-x4420
Search vendor "Carrier" for product "Lenels2 Lnl-x4420"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 S2-lp-1501 Firmware
Search vendor "Carrier" for product "Lenels2 S2-lp-1501 Firmware"
< 1.271
Search vendor "Carrier" for product "Lenels2 S2-lp-1501 Firmware" and version " < 1.271"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 S2-lp-1501
Search vendor "Carrier" for product "Lenels2 S2-lp-1501"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 S2-lp-1502 Firmware
Search vendor "Carrier" for product "Lenels2 S2-lp-1502 Firmware"
< 1.271
Search vendor "Carrier" for product "Lenels2 S2-lp-1502 Firmware" and version " < 1.271"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 S2-lp-1502
Search vendor "Carrier" for product "Lenels2 S2-lp-1502"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 S2-lp-2500 Firmware
Search vendor "Carrier" for product "Lenels2 S2-lp-2500 Firmware"
< 1.271
Search vendor "Carrier" for product "Lenels2 S2-lp-2500 Firmware" and version " < 1.271"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 S2-lp-2500
Search vendor "Carrier" for product "Lenels2 S2-lp-2500"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 S2-lp-4502 Firmware
Search vendor "Carrier" for product "Lenels2 S2-lp-4502 Firmware"
< 1.271
Search vendor "Carrier" for product "Lenels2 S2-lp-4502 Firmware" and version " < 1.271"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 S2-lp-4502
Search vendor "Carrier" for product "Lenels2 S2-lp-4502"
--
Safe