CVE-2022-48074: Medium severity nomachine vulnerability
Published Feb 3, 2023
·Updated
An issue in NoMachine before v8.2.3 allows attackers to execute arbitrary commands via a crafted .nxs file.
Affected Software
1 affected component
NoMachine NoMachine<8.2.3
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this NoMachine issue?
The vulnerability ID for this NoMachine issue is CVE-2022-48074.
2
What is the severity of CVE-2022-48074?
The severity of CVE-2022-48074 is medium with a CVSS score of 5.3.
3
Which versions of NoMachine are affected by CVE-2022-48074?
NoMachine versions up to and excluding 8.2.3 are affected by CVE-2022-48074.
4
How can an attacker exploit CVE-2022-48074?
An attacker can exploit CVE-2022-48074 by crafting a malicious .nxs file to execute arbitrary commands.
5
How can I fix CVE-2022-48074 in NoMachine?
To fix CVE-2022-48074, update NoMachine to version 8.2.3 or higher.