CVE-2022-29303: SolarView Compact Command Injection Vulnerability
SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.
Other sources
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via confmail.php.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If vendor updates are unavailable, discontinue use of Contec SolarView Compact version 6.00.
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-29303.
What is the title of this vulnerability?
The title of this vulnerability is SolarView Compact Command Injection Vulnerability.
What is the description of this vulnerability?
SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.
What is the affected software?
The affected software includes Contec Sv-cpt-mc310 Firmware version 6.00 and SolarView Compact.
What is the severity of this vulnerability?
The severity of this vulnerability is critical with a CVSS score of 9.8.
How can I fix this vulnerability?
Apply the latest security patch or update provided by SolarView.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [1](http://packetstormsecurity.com/files/167183/SolarView-Compact-6.0-Command-Injection.html), [2](https://drive.google.com/drive/folders/1tGr-WExbpfvhRg31XCoaZOFLWyt3r60g?usp=sharing), [3](https://jvn.jp/en/vu/JVNVU92327282/).