CVE-2022-38156
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admin user, an attacker can send a crafted password in order to execute Linux commands as the root user.
Affected (1)
Products: Kratosdefense: Spectralnet Narrowband Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.7.5 |
| Running on/with | Platform Versions |
|---|---|
Kratosdefense Spectralnet Narrowband | All versions |
References (2)
Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Timeline
No history available yet.