Back to Database
Status published
High
CVE-2022-40969
An os command injection vulnerability exists in the httpd delfile.cgi...
Vulnerability Description
An os command injection vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-40969
Credits & Attribution
No credits recorded in the NVD database.
More from Siretta
View All →CVE-2022-42493
Several OS command injection vulnerabilities exist in the m2m binary...
Critical
9.8
CVE-2022-42492
Several OS command injection vulnerabilities exist in the m2m binary...
Critical
9.8
CVE-2022-42491
Several OS command injection vulnerabilities exist in the m2m binary...
Critical
9.8
CVE-2022-42490
Several OS command injection vulnerabilities exist in the m2m binary...
Critical
9.8
CVE-2022-41991
A heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE...
Critical
9.8
Affected Vendor
Siretta
View all reports →Affected Software
QUARTZ-GOLD
Vulnerable Versions:
G5.0.1.5-210720-141020
Timeline
Official Publish:
January 26th, 2023
Last Modified:
March 27th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H