CVE-2022-26482: OS Command Injection
Published Jul 17, 2022
·Updated
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.
Affected Software
2 affected components
Poly Eagleeye Director Ii Firmware<2.2.2.1
Poly EagleEye Director II
Event History
Jul 17, 2022
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-26482?
CVE-2022-26482 has a high severity rating due to the potential for command injection by an authenticated admin.
2
How do I fix CVE-2022-26482?
To fix CVE-2022-26482, upgrade Poly EagleEye Director II to version 2.2.2.1 or later.
3
Who is affected by CVE-2022-26482?
Administrators of Poly EagleEye Director II versions prior to 2.2.2.1 are affected by CVE-2022-26482.
4
What vulnerabilities are associated with CVE-2022-26482?
CVE-2022-26482 is associated with the potential for arbitrary command execution through os.system command injection.
5
Is there a workaround for CVE-2022-26482?
There are no known workarounds for CVE-2022-26482 other than applying the recommended software update.