Back

CRITICAL

Remote code execution in scheduled tasks component

Published Aug 16, 2022

Description

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

Affected products

Remediation

Vendor solution

An update to version 18.01.00 fixes the issue

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Bitdefender
Published Aug 16, 2022
Updated Sep 16, 2024
Reserved Apr 19, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Bitdefender
Published Aug 16, 2022
Updated Sep 16, 2024
Exploited since n/a
EUVD-2022-24715