HOMEVULNERABILITIESCVE-2018-1002208
MEDIUM

CVE-2018-1002208

CWE-22Published: July 25, 2018· Updated: Jun 17, 2026

5.5
CVSS v3.1

Official Description

SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

NVD Source

Technical Analysis

CVE-2018-1002208 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation does not require any privileges, though user interaction (Required) is needed, which slightly reduces the risk of mass automated attacks.

A successful exploit results in full integrity compromise (data manipulation), with a CVSS base score of 5.5.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorLocal
Attack ComplexityLow
Privileges Req.None
User InteractionRequired
ScopeUnchanged
Impact
ConfidentialityNone
IntegrityHigh
AvailabilityNone
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected Vendors & Products

sharpziplib
Source: NVD CPE · 1 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

News & Research Mentioning CVE-2018-1002208

Hitachi Energy PCM600
CISA Alerts· May 5, 2026

View CSAF Summary Hitachi Energy is aware of a vulnerability that affects the Hitachi Energy PCM600 product versions listed in this document. An attacker successfully exploiting this vulnerability can impact integrity of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy PCM600 are affected: PCM600 Legacy vers:PCM600_Legacy/<=2.11 (CVE-2018-1002208) PCM600 3.0, 3.0_HF1, 3.0_HF2, 3.0_HF3, 3.1, 3.1_SP1, 3.1_SP2, 3.1_SP3 (CVE-2018-1002208, CVE-2018-1002208, CVE-2018-1002208, CVE-2018-1002208, CVE-2018-1002208, CVE-2018-1002208, CVE-2018-1002208, CVE-2018-1002208) CVSS Vendor Equipment Vulnerabilities v3 4.4 Hitachi Energy Hitachi Energy PCM600 Improper [xlite_meta score:69 src:CISA Alerts xlite_fp:9b0c9b9559b74535ae59add0cfe2d2414a0b5e3779499e1b6221d6b90173ae87]

ABB PCM600
CISA Alerts· Apr 30, 2026

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to send specially crafted messages to the system node resulting in execution of arbitrary code. The following versions of ABB PCM600 are affected: PCM600 >=1.5| =1.5|<=2.13 Product Status: known_affected Remediations Vendor fix The problem is corrected in the following product version: ABB Protection and control IED manager PCM600 version 2.14. ABB recommends that customers apply the update at earliest convenience. Vendor fix Note: RE_630 protection relays are not compatible with PCM600 version 2.14. When using earlier PCM600 versions with RE_630, the known vulnerability must be mitigated through system-level defenses. For mitigation guidance, refer to the General [xlite_meta score:79 src:CISA Alerts xlite_fp:85b4e5927cda5dfc1178e27097dd5dec76edb8451f86081af760d234413aaafb]

All References (10)

https://github.com/icsharpcode/SharpZipLib/issues/232Issue Tracking · Patch · Third Party Advisory
https://github.com/icsharpcode/SharpZipLib/wiki/Release-1.0Issue Tracking · Patch · Third Party Advisory
https://snyk.io/vuln/SNYK-DOTNET-SHARPZIPLIB-60247Exploit · Patch · Technical Description
https://github.com/icsharpcode/SharpZipLib/issues/232Issue Tracking · Patch · Third Party Advisory
https://github.com/icsharpcode/SharpZipLib/wiki/Release-1.0Issue Tracking · Patch · Third Party Advisory
https://snyk.io/vuln/SNYK-DOTNET-SHARPZIPLIB-60247Exploit · Patch · Technical Description

Quick Facts

CVE IDCVE-2018-1002208
CVSS Score5.5 / 10
SeverityMEDIUM
WeaknessCWE-22
CISA KEVNo
Affected1 vendor(s)
PublishedJul 25, 2018

Related CVEs (CWE-22)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2018-1002208 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.