First published: Tue Sep 27 2022(Updated: )
Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wazuh | >=3.6.1<=3.13.5 | |
Wazuh | >=4.0.0<=4.2.7 | |
Wazuh | >=4.3.0<=4.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-40497.
The severity of CVE-2022-40497 is high. (CVSS score: 8.8)
The affected software is Wazuh versions 3.6.1 - 3.13.5, 4.0.0 - 4.2.7, and 4.3.0 - 4.3.7.
CVE-2022-40497 is an authenticated remote code execution (RCE) vulnerability in Wazuh via the Active Response endpoint.
Update Wazuh to a version that is not affected. Refer to the vendor's website for patches and upgrades.