CVE-2022-3086: Cradlepoint IBR600 Command Injection
Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3086?
CVE-2022-3086 is classified as a critical vulnerability that allows local attackers to gain full shell access.
How do I fix CVE-2022-3086?
To fix CVE-2022-3086, upgrade to the latest version of Cradlepoint IBR600 NCOS beyond version 6.5.0.160bc2e.
Who is affected by CVE-2022-3086?
CVE-2022-3086 affects Cradlepoint IBR600 NetCloud OS (NCOS) versions 6.5.0.160bc2e and earlier.
What could an attacker do with CVE-2022-3086?
An attacker exploiting CVE-2022-3086 can execute arbitrary code by gaining unrestricted shell access.
What is the impact of CVE-2022-3086 on systems?
The impact of CVE-2022-3086 includes potential loss of confidentiality, integrity, and system availability due to unauthorized access.