CVE-2021-22646

The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.

Credits

Uri Katz of Claroty reported these vulnerabilities to CISA.

References