Hidden functionality in FLEXLAN FX3000 series and FLEXLAN FX2000 series - CVE-2022-36158

 

Hidden functionality in FLEXLAN FX3000 series and FLEXLAN FX2000 series - CVE-2022-36158

Published: September 1, 2022


Vulnerability identifier: #VU66917
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36158
CWE-ID: CWE-912
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system

The vulnerability exists due to hidden functionality (backdoor) is present in software. A remote user on the local network can use this functionality to gain full access to the application and execute arbitrary OS command with an administrative privileges.


Affected software

FLEXLAN FX3000 series
FLEXLAN FX2000 series

How to mitigate CVE-2022-36158

Install updates from vendor's website.

FLEXLAN FX3000 series - update to 1.16.00
FLEXLAN FX2000 series - update to 1.39.00

External References

Related Security Bulletins