CVE-2022-0551: Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0
Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-0551.
What is the severity of CVE-2022-0551?
The severity of CVE-2022-0551 is high.
Which software versions are affected by CVE-2022-0551?
Nozomi Networks Guardian versions up to exclusive 22.0.0 and Nozomi Networks CMC versions up to exclusive 22.0.0 are affected by CVE-2022-0551.
How can an authenticated attacker exploit CVE-2022-0551?
An authenticated attacker with admin or import manager roles can exploit CVE-2022-0551 by executing unattended commands on the appliance using web server user privileges.
Is there any fix available for CVE-2022-0551?
Please refer to the vendor's website for the available fix for CVE-2022-0551.