Input validation error in SiPass integrated ACC-AP and SiPass integrated AC5102 - CVE-2022-31808
Published: February 20, 2023 / Updated: February 22, 2023
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input in the telnet command line interface. A local user can pass specially crafted input to the application and execute arbitrary commands on the target system with elevated privileges.
Affected software
SiPass integrated AC5102
SiPass integrated AC5100
SiPass integrated AC5200
SiPass integrated Granta-MK3
How to mitigate CVE-2022-31808
SiPass integrated AC5102 - update to 2.85.44