CRITICAL
Remote code execution in scheduled tasks component
Published Aug 16, 2022
9.1
CRITICALCVSS 3.1
EPSS 0.91%
Description
An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<18.01.00
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
An update to version 18.01.00 fixes the issue
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24715 Advisory
- https://www.bitdefender.com/blog/labs/a-red-team-perspective-on-the-device42-asset-management-appliance/ x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24715 | Advisory | |
| https://www.bitdefender.com/blog/labs/a-red-team-perspective-on-the-device42-asset-management-appliance/ | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Bitdefender
Published Aug 16, 2022
Updated Sep 16, 2024
Reserved Apr 19, 2022
Link CVE-2022-1399
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-24715 Assigner Bitdefender
Published Aug 16, 2022
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2022-24715