CVE-2022-46640: Command Injection
Published Apr 18, 2023
·Updated
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
Affected Software
1 affected component
Nanoleaf Nanoleaf Desktop<1.3.1
Event History
Apr 18, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-46640.
2
What is the severity of CVE-2022-46640?
The severity of CVE-2022-46640 is critical (9.8/10).
3
What is the affected software?
The affected software is Nanoleaf Desktop App version up to and exclusive 1.3.1.
4
How does the command injection vulnerability in CVE-2022-46640 get exploited?
The command injection vulnerability in CVE-2022-46640 is exploited via a crafted HTTP request.
5
How can I fix the vulnerability in Nanoleaf Desktop App?
To fix the vulnerability in Nanoleaf Desktop App, update to version 1.3.1 or later.