« Volver al listado

CVE-2022-4636

Estado: ModificadaAlta (7.5)—

Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-4636",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-4636",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-16T20:57:34.349118Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "Black Box",
          "product": "KVM ACR1020A-T",
          "versions": [
            {
              "status": "affected",
              "version": "3.4.31307"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Black Box",
          "product": "KVM ACR1002A-R",
          "versions": [
            {
              "status": "affected",
              "version": "3.4.31307"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Black Box",
          "product": "KVM ACR1002A-T",
          "versions": [
            {
              "status": "affected",
              "version": "3.4.31307"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Black Box",
          "product": "KVM ACR1000A-T-R2",
          "versions": [
            {
              "status": "affected",
              "version": "3.4.31307"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Black Box",
          "product": "KVM ACR1000A-R-R2",
          "versions": [
            {
              "status": "affected",
              "version": "3.4.31307"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-01-10T20:15:10.607",
  "references": [
    {
      "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-010-01",
      "tags": [
        "Patch",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-010-01",
      "tags": [
        "Patch",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.\n\n"
    },
    {
      "lang": "es",
      "value": "La versión 3.4.31307 de Black Box KVM Firmware en los modelos ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R y ACR1020A-T es vulnerable a path traversal, lo que puede permitir a un atacante robar credenciales de usuario y otra información confidencial mediante la inclusión de archivos locales."
    }
  ],
  "lastModified": "2026-06-17T05:21:25.193",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:blackbox:acr1000a-r-r2_firmware:3.4.31307:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64D27D88-2CDC-4EAC-9A39-49F98C560797"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:blackbox:acr1000a-r-r2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6FBCC884-104B-47F4-B08A-72AA0A25E898"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:blackbox:acr1000a-t-r2_firmware:3.4.31307:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8435BA5-8175-4651-8949-37F5DA16F534"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:blackbox:acr1000a-t-r2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "94A9F274-7071-42E0-ABC7-FA2F9595B043"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:blackbox:acr1002a-r_firmware:3.4.31307:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A20579B5-23B4-4AA6-8E7C-9A3402994BA0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:blackbox:acr1002a-r:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "60C8325E-05DF-497C-8396-5838530C6807"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:blackbox:acr1002a-t_firmware:3.4.31307:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00C283C2-B1DB-4EED-B9D5-9FA3E57F14D2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:blackbox:acr1002a-t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B7F68C48-1D3E-4071-8C42-E4816D43A1A6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:blackbox:acr1020a-t_firmware:3.4.31307:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05618BE3-FBAB-422A-86BF-78F1FB71032F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:blackbox:acr1020a-t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "955FBC9D-2B5B-4333-9B34-41D19036BD64"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}