CVE-2022-0902
published 2022-07-21CVE-2022-0902: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command…
PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
16.36%
96.6th percentile
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | rmc-100 | >= unspecified < 2105457-037 | 2105457-037 |
| abb | rmc-100-lite | >= unspecified < 2106229-011 | 2106229-011 |
| abb | rmc-100-lite_firmware | < 2106229-011 | 2106229-011 |
| abb | rmc-100_firmware | < 2105457-037 | 2105457-037 |
| abb | udc | >= unspecified < 2106177-007 | 2106177-007 |
| abb | udc_firmware | < 2106177-007 | 2106177-007 |
| abb | uflog5 | >= unspecified < 2105298-024 | 2105298-024 |
| abb | uflog5_firmware | < 2105298-024 | 2105298-024 |
| abb | xfcg5 | >= unspecified < 2105805-016 | 2105805-016 |
| abb | xfcg5_firmware | < 2105805-016 | 2105805-016 |
| abb | xio | >= unspecified < 2106198-008 | 2106198-008 |
| abb | xio_firmware | < 2106198-008 | 2106198-008 |
| abb | xrcg5 | >= unspecified < 2105864-016 | 2105864-016 |
| abb | xrcg5_firmware | < 2105864-016 | 2105864-016 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-0902 is a path-traversal and command injection vulnerability in ABB Totalflow systems (RMC-100, RMC-100-LITE, XIO, XFCG5, XRCG5, uFLOG5, UDC) used in oil and gas organizations; exploitation allows arbitrary code injection and execution on affected system nodes. ↗
- ·Affected products include ABB RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5, XRCG5, uFLOG5, and UDC flow computers and remote controllers; detections should be scoped to these specific device types in OT/ICS environments. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Checkpoint
14th November– Threat Intelligence Report
blogs_checkpoint·2022-11-14
CVE-2022-20465 14th November– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th November– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The Australian Federal Police has disclosed that the hacking group responsible for the massive Medibank hack that compromised the personal information of 9.7 million customers is based in Russia. The group’s identity was not yet published.
Black Basta ransomware group has launched a cyberattack against Canadian grocery
Checkpoint
14th November– Threat Intelligence Report
blogs_checkpoint·2022-11-14
CVE-2022-20465 14th November– Threat Intelligence Report
Top Attacks and Breaches
The Australian Federal Police has disclosed that the hacking group responsible for the massive Medibank hack that compromised the personal information of 9.7 million customers is based in Russia. The group’s identity was not yet published.
Black Basta ransomware group has launched a cyberattack against Canadian grocery and pharmacy chain store Sobeys, impacting some of the company’s in-store services and operations.
Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Banker.Wins.Carbanak.*; Ransomware.Win.BlackBasta.*)
Security Researchers have disclosed two new surveillance campaigns targeting Uyghurs in the People’s Republic of China and abroad with BadBazaar and MOONSHINE spyware.
Threat actors are mass spreading scam e
2022-07-21
Published