Description
An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
An update to version 18.01.00 fixes the issue
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24715 | An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions. |
References
History
No history.
Status: PUBLISHED
Assigner: Bitdefender
Published:
Updated: 2024-09-16T23:51:14.975Z
Reserved: 2022-04-19T00:00:00.000Z
Link: CVE-2022-1399
No data.
Status : Modified
Published: 2022-08-17T00:15:08.057
Modified: 2024-11-21T06:40:39.170
Link: CVE-2022-1399
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD