OS Command Injection in SMA 100 - CVE-2022-1703
Published: May 18, 2022
Vulnerability identifier: #VU63353
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1703
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improper input validation in the management interface interface. A remote authenticated user can pass specially crafted data to the application and execute arbitrary OS commands on the target system with root privileges.
Affected software
SMA 100
How to mitigate CVE-2022-1703
Install updates from vendor's website.
SMA 100 - addressed in versions 10.2.0.10-46sv, 10.2.1.5-34sv