// For flags

CVE-2022-1399

Remote code execution in scheduled tasks component

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

Una vulnerabilidad de Inyección o Modificación de Argumentos en el campo de nombre de usuario "Change Secret" usado en el componente Discovery de Device42 CMDB permite a un atacante local ejecutar código arbitrario en el dispositivo con privilegios root. Este problema afecta: Device42 CMDB versión 18.01.00 y versiones anteriores.

*Credits: Ștefania POPESCU - Team Lead, Security @ Bitdefender, Ionuț LALU - Security Engineer @ Bitdefender, Cristian BUZA - Security Engineer @ Bitdefender, Alexandru LAZĂR - Security Researcher @ Bitdefender
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Multiple
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-04-19 CVE Reserved
  • 2022-08-16 CVE Published
  • 2024-09-16 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Device42
Search vendor "Device42"
Cmdb
Search vendor "Device42" for product "Cmdb"
< 18.01.00
Search vendor "Device42" for product "Cmdb" and version " < 18.01.00"
-
Affected