CVE-2022-4572 is a path traversal vulnerability in UBI Reader versions up to 0.8.0, specifically within the ubireader_extract_files function of the UBIFS File Handler component. This flaw allows a remote attacker to manipulate file paths, potentially leading to unauthorized file creation or modification outside of the intended directory. With a CVSS score of 7.1 (High), the vulnerability requires user interaction (UI:R) but can result in high integrity and availability impacts (I:H, A:H). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.8.0CPE matchmatch criteria | cpe:2.3:a:ubi_reader_project:ubi_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.