PT-2022-27265 · Unknown · Diagnosis Controller

·

CVE-2022-44621

·

Published

2022-12-30

·

Updated

2023-01-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Diagnosis Controller (affected versions not specified)
Description The issue concerns a lack of parameter validation in the Diagnosis Controller, which can be exploited through command injection via HTTP Request. This allows an attacker to inject malicious commands, potentially leading to unauthorized access or control.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-44621
GHSA-W9RV-XMF7-X3GH

Affected Products

Diagnosis Controller