CVE-2022-45701: Command Injection
Published Feb 17, 2023
·Updated
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
Affected Software
12 affected components
All of the following
CommScope Arris Tg2482a Firmware<=9.1.103
CommScope Arris Tg2482a
All of the following
CommScope Arris Tg2492 Firmware<=9.1.103
CommScope Arris Tg2492
All of the following
CommScope Arris Sbg10 Firmware<=9.1.103
CommScope Arris Sbg10
CommScope Arris Tg2482a Firmware<=9.1.103
CommScope Arris Tg2482a
CommScope Arris Tg2492 Firmware<=9.1.103
CommScope Arris Tg2492
CommScope Arris Sbg10 Firmware<=9.1.103
CommScope Arris Sbg10
Event History
Feb 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-45701.
2
What is the severity of CVE-2022-45701?
The severity of CVE-2022-45701 is high.
3
How does CVE-2022-45701 allow Remote Code Execution (RCE)?
CVE-2022-45701 allows Remote Code Execution (RCE) through the ping utility feature in Arris TG2482A firmware.
4
Which software versions are affected by CVE-2022-45701?
Arris TG2482A firmware versions up to 9.1.103GEM9 are affected by CVE-2022-45701.
5
How can I fix CVE-2022-45701?
To fix CVE-2022-45701, update your Arris TG2482A firmware to version 9.1.103GEM9 or higher.