Security Advisory

CVE-2022-35244

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-10-25 16:34:01
Last updated 2025-04-15 18:45:04
Assigner talos
State PUBLISHED

Description

A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.