CVE-2022-45140

Published Feb 27, 2023

Last updated 2 years ago

Overview

Description
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
Source
info@cert.vde.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

info@cert.vde.com
CWE-306

Social media

Hype score
Not currently trending

Configurations