CVE-2022-25619: Authenticated Command Injection to RCE
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25619?
CVE-2022-25619 has a high severity rating due to its potential for command injection leading to arbitrary code execution.
How do I fix CVE-2022-25619?
To fix CVE-2022-25619, upgrade Profelis IT Consultancy SambaBox to a version newer than 4.0.
Who is affected by CVE-2022-25619?
CVE-2022-25619 affects authenticated users of Profelis IT Consultancy SambaBox version 4.0 and prior.
What is the nature of the vulnerability in CVE-2022-25619?
CVE-2022-25619 is characterized by improper neutralization of special elements leading to command injection.
Can unauthorized users exploit CVE-2022-25619?
No, CVE-2022-25619 can only be exploited by authenticated users.