CVE-2022-0551
Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.
Una vulnerabilidad de comprobaciĆ³n de entrada inapropiada en la carga de archivos de proyectos en Nozomi Networks Guardian y CMC permite a un atacante autenticado con roles de administrador o administrador de importaciones ejecutar comandos desatendidos en el dispositivo usando privilegios de usuario del servidor web. Este problema afecta a: Nozomi Networks Guardian versiones anteriores a 22.0.0. Nozomi Networks CMC versiones anteriores a 22.0.0
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2022-02-09 CVE Reserved
- 2022-03-24 CVE Published
- 2023-10-15 EPSS Updated
- 2024-09-20 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
- CAPEC-88: OS Command Injection
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.nozominetworks.com/NN-2022:2-02 | 2024-05-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nozominetworks Search vendor "Nozominetworks" | Cmc Search vendor "Nozominetworks" for product "Cmc" | < 22.0.0 Search vendor "Nozominetworks" for product "Cmc" and version " < 22.0.0" | - |
Affected
| ||||||
Nozominetworks Search vendor "Nozominetworks" | Guardian Search vendor "Nozominetworks" for product "Guardian" | < 22.0.0 Search vendor "Nozominetworks" for product "Guardian" and version " < 22.0.0" | - |
Affected
|