Back to Database
Status published
Medium
CVE-2022-40701
A directory traversal vulnerability exists in the httpd delfile.cgi functionality...
Vulnerability Description
A directory traversal vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-40701
Credits & Attribution
No credits recorded in the NVD database.
More from Siretta
View All →CVE-2022-42493
Several OS command injection vulnerabilities exist in the m2m binary...
Critical
9.8
CVE-2022-42492
Several OS command injection vulnerabilities exist in the m2m binary...
Critical
9.8
CVE-2022-42491
Several OS command injection vulnerabilities exist in the m2m binary...
Critical
9.8
CVE-2022-42490
Several OS command injection vulnerabilities exist in the m2m binary...
Critical
9.8
CVE-2022-41991
A heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE...
Critical
9.8
Affected Vendor
Siretta
View all reports →Affected Software
QUARTZ-GOLD
Vulnerable Versions:
G5.0.1.5-210720-141020
Timeline
Official Publish:
January 26th, 2023
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H