CVE-2022-37912
🟡 Monitoruj
Wstrzyknięcie poleceń w ArubaOS umożliwia wykonanie dowolnych komend jako użytkownik uprzywilejowany.
CVSS
7.2
EPSS
1.6%
Exploit
none
Vendor
arubanetworks
Opis źródłowy (NVD)
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.2 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.6% |
| Opublikowano (NVD) | 2022-12-12 13:15:13 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 17:14:45 UTC |
Referencje
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt ([email protected]) [Vendor Advisory]