Hidden functionality in FLEXLAN FX3000 series and FLEXLAN FX2000 series - CVE-2022-36158
Published: September 1, 2022
Vulnerability identifier: #VU66917
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36158
CWE-ID: CWE-912
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system
The vulnerability exists due to hidden functionality (backdoor) is present in software. A remote user on the local network can use this functionality to gain full access to the application and execute arbitrary OS command with an administrative privileges.
Affected software
FLEXLAN FX3000 series
FLEXLAN FX2000 series
FLEXLAN FX2000 series
How to mitigate CVE-2022-36158
Install updates from vendor's website.
FLEXLAN FX3000 series - update to 1.16.00
FLEXLAN FX2000 series - update to 1.39.00
FLEXLAN FX2000 series - update to 1.39.00