CVE-2022-36509: OS Command Injection
Published Aug 25, 2022
·Updated
H3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
Affected Software
4 affected components
H3C Gr3200 Firmware=minigr1b0v100r014
H3C GR3200
All of the following
H3C Gr3200 Firmware=minigr1b0v100r014
H3C GR3200
Event History
Aug 25, 2022
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-36509?
CVE-2022-36509 is classified as a critical command injection vulnerability that allows remote attackers to execute arbitrary commands.
2
How do I fix CVE-2022-36509?
To remediate CVE-2022-36509, update the H3C GR3200 firmware to the latest version that addresses this vulnerability.
3
What affected software versions are impacted by CVE-2022-36509?
CVE-2022-36509 specifically affects H3C GR3200 firmware version minigr1b0v100r014.
4
What kind of vulnerability is CVE-2022-36509?
CVE-2022-36509 is a command injection vulnerability that can be exploited through the param parameter.
5
Who is the vendor for CVE-2022-36509?
The vendor for CVE-2022-36509 is H3C, which produces the GR3200 series of devices.