CVE-2022-31483

HIGH

An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability impacts products ...

Affects 28 products across 3 vendors.

BCS7.19
CVSS 3.18.8
EPSS1.6%
Percentile74th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-22: Path Traversal

Attacker manipulates file path inputs to access files outside the intended directory.

Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-22
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-22
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-22
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-22
CAPEC-126 Path Traversal
via CWE-22

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2022-31483 affects HID Mercury Intelligent Controllers, allowing an authenticated attacker to upload files with crafted filenames to overwrite system files and gain root access. The vulnerability impacts firmware versions prior to 1.271 and has a CVSS score of 8.8.

BSID: BS-2022-GLOBAL-319388-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-31483?
CVE-2022-31483 affects HID Mercury Intelligent Controllers, allowing an authenticated attacker to upload files with crafted filenames to overwrite system files and gain root access. The vulnerability impacts firmware versions prior to 1.271 and has a CVSS score of 8.8.
What is the CVSS score for CVE-2022-31483?
CVE-2022-31483 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.6%.
Is CVE-2022-31483 actively exploited?
No confirmed active exploitation of CVE-2022-31483 as of 2026-05-30.
How do I remediate CVE-2022-31483?
Priority: HIGH. Advisory: https://www.corporate.carrier.com/product-security/advisories-resources/ PSIRT: [email protected]
What systems are affected by CVE-2022-31483?
CVE-2022-31483 affects: Carrier, Carrier, Carrier, Carrier, Carrier, Carrier, Carrier, Carrier.
What NERC-CIP standard applies to CVE-2022-31483?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized modification of system files, which could compromise the integrity and availability of the control system.
What IEC 62443 requirement maps to CVE-2022-31483?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves the protection of system files from unauthorized modification, which is crucial for maintaining the security and reliability of the industrial control system.
Vulnerability Details
CVE IDCVE-2022-31483
BSIDBS-2022-GLOBAL-319388-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2022-06-06
Last Modified2024-11-21
ICS Relevance90%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.271. This allows a malicious actor to overwrite sensitive system files and install a startup service to gain remote access to the underlaying Linux operating system with root privileges.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An authenticated attacker can exploit this vulnerability by uploading a file with a filename containing “..” and “/”. This allows the attacker to place the file anywhere on the filesystem, potentially overwriting critical system files and installing a startup service to gain remote root access to the underlying Linux operating system.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Carrier Lenels2 S2-Lp-4502
Carrier Lenels2 Lnl-4420 Firmware
Carrier Lenels2 Lnl-4420
Carrier Lenels2 Lnl-X2210 Firmware
Carrier Lenels2 Lnl-X2210
Carrier Lenels2 Lnl-X2220 Firmware
Carrier Lenels2 Lnl-X2220
Carrier Lenels2 Lnl-X3300 Firmware
Carrier Lenels2 Lnl-X3300
Carrier Lenels2 Lnl-X4420 Firmware
Carrier Lenels2 Lnl-X4420
Carrier Lenels2 S2-Lp-1501 Firmware
Carrier Lenels2 S2-Lp-1501
Carrier Lenels2 S2-Lp-1502 Firmware
Carrier Lenels2 S2-Lp-1502
Carrier Lenels2 S2-Lp-2500 Firmware
Carrier Lenels2 S2-Lp-2500
Carrier Lenels2 S2-Lp-4502 Firmware
Hidglobal Ep4502
Hidglobal Lp1501 Firmware
Hidglobal Lp1501
Hidglobal Lp1502 Firmware
Hidglobal Lp1502
Hidglobal Lp2500 Firmware
Hidglobal Lp2500
Hidglobal Lp4502 Firmware
Hidglobal Lp4502
Hidglobal Ep4502 Firmware
Honeywell —
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1510 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict file upload validation and restrict file paths to a designated directory. Ensure that only authorized users can upload files and monitor file upload activities for suspicious patterns.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized modification of system files, which could compromise the integrity and availability of the control system.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves the protection of system files from unauthorized modification, which is crucial for maintaining the security and reliability of the industrial control system.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash7bda23a1e3253635f8b2cbf0ba547a3264a98b5605e21b1474bd74f3ad55e1a43aa86bf4ba0b3c6a01223f2fcb5d2d0160aae898485aef773dac705a12ff3718
Related CVEs affecting Carrier
CVE-2022-31481 10.0 An unauthenticated attacker can send a specially crafted update file to the d... CVE-2025-53213 9.9 Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions... CVE-2022-31479 9.8 An unauthenticated attacker can update the hostname with a specially crafted ... CVE-2022-31486 8.8 An authenticated attacker can send a specially crafted route to the “edit_rou... CVE-2017-9650 7.8 An Unrestricted Upload of File with Dangerous Type issue was discovered in Au...
View all Carrier CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →