Arbitrary Service Control Vulnerability in Sewio’s RTLS Studio

Arbitrary Service Control Vulnerability in Sewio’s RTLS Studio

CVE-2022-43455 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to the service_start, service_stop, and service_restart modules of the software. This could allow an attacker to start, stop, or restart arbitrary services running on the server.

Learn more about our Cis Benchmark Audit For Server Software.