The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://www.primeur.com/managed-file-transfer | vendor advisory |
https://github.com/Off3nS3c/CVE-2022-29932/blob/main/Proof-of-Concept.md | third party advisory exploit |