Arbitrary File Deletion and Denial-of-Service Vulnerability in Sewio RTLS Studio

Arbitrary File Deletion and Denial-of-Service Vulnerability in Sewio RTLS Studio

CVE-2022-47917 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to several modules and services of the software. This could allow an attacker to delete arbitrary files and cause a denial-of-service condition.

Learn more about our User Device Pen Test.