CVE-2022-23317: High severity cobalt strike vulnerability
Published Feb 15, 2022
·Updated
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
Affected Software
1 affected component
HelpSystems Cobalt Strike<4.5
Event History
Feb 15, 2022
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-23317?
The severity of CVE-2022-23317 is high, with a severity value of 7.5.
2
What is the vulnerability in CobaltStrike <=4.5?
The vulnerability in CobaltStrike <=4.5 is that the HTTP(S) listener does not determine whether the request URL begins with '/'.
3
How can attackers exploit CVE-2022-23317?
Attackers can exploit CVE-2022-23317 by specifying the URL and obtaining relevant information.
4
What is the affected software for CVE-2022-23317?
The affected software for CVE-2022-23317 is HelpSystems Cobalt Strike version up to exclusive 4.5.
5
Is there a fix available for CVE-2022-23317?
Yes, a fix is available for CVE-2022-23317. It is recommended to update to a version higher than 4.5.