PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-2265 Çekino Bilgi Teknolojileri CVE debrief

An unauthenticated path traversal vulnerability in the Identity and Directory Management System developed by Çekino Bilgi Teknolojileri allows remote attackers to read arbitrary files on affected systems. The vulnerability exists in versions prior to 2.1.25 and has been assigned a CVSS 3.1 score of 7.5 (HIGH severity). The issue was publicly disclosed on September 21, 2022, and subsequently modified in the NVD on May 20, 2026. Turkish government cybersecurity authorities (USOM and siberguvenlik.gov.tr) issued security advisories tracking this vulnerability as TR-22-0636. The vendor has released version 2.1.25 to address this vulnerability.

Vendor
Çekino Bilgi Teknolojileri
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2022-09-21
Original CVE updated
2026-05-20
Advisory published
2022-09-21
Advisory updated
2026-05-20

Who should care

Organizations running Identity and Directory Management System versions prior to 2.1.25; security teams managing identity infrastructure; Turkish government and critical infrastructure operators monitored by USOM; any organization with externally exposed instances of this directory management platform.

Technical summary

The Identity and Directory Management System by Çekino Bilgi Teknolojileri contains an unauthenticated path traversal vulnerability that enables remote attackers to access arbitrary files on the underlying file system. The vulnerability is network-exploitable without authentication, with low attack complexity. The confidentiality impact is rated HIGH, while integrity and availability impacts are NONE. The affected product is an identity and directory management solution, suggesting potential exposure of sensitive authentication data, configuration files, or system credentials if exploited. The fix version 2.1.25 was released to remediate this vulnerability.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade Identity and Directory Management System to version 2.1.25 or later
  • Review access logs for suspicious file access patterns indicating path traversal attempts
  • Implement network segmentation to limit exposure of directory management interfaces
  • Apply principle of least privilege to file system permissions on hosts running the affected application
  • Monitor for unauthorized file access attempts via web application firewall or intrusion detection systems

Evidence notes

CVE published 2022-09-21; NVD record modified 2026-05-20. CPE confirms affected versions: all versions prior to 2.1.25. CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Weaknesses identified as CWE-35 (Path Traversal) and CWE-22 (Improper Limitation of a Pathname to a Restricted Directory).

Official resources

2022-09-21