« Volver al listado

CVE-2022-30621

Estado: ModificadaMedia (6.5)—

Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS as root user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-30621",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@cyber.gov.il",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@cyber.gov.il",
      "affectedData": [
        {
          "vendor": "Cellinx",
          "product": "Cellinx NVT - IP PTZ Camera",
          "versions": [
            {
              "status": "affected",
              "version": "3.2.1",
              "lessThan": "3.2.0*",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-07-18T13:15:10.007",
  "references": [
    {
      "url": "https://www.gov.il/en/departments/faq/cve_advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cna@cyber.gov.il"
    },
    {
      "url": "https://www.gov.il/en/departments/faq/cve_advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-706"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Allows a remote user to read files on the camera's OS \"GetFileContent.cgi\". Reading arbitrary files on the camera's OS as root user."
    },
    {
      "lang": "es",
      "value": "Permite a un usuario remoto leer archivos en el SO de la cámara \"GetFileContent.cgi\". Leer archivos arbitrarios en el SO de la cámara como usuario root"
    }
  ],
  "lastModified": "2026-06-17T04:43:57.570",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cellinx:cellinx_nvt_-_ip_ptz_camera_firmware:3.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D899A4D-7326-4A61-89DE-B86E34E9FD05"
            },
            {
              "criteria": "cpe:2.3:o:cellinx:cellinx_nvt_-_ip_ptz_camera_firmware:3.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "358412ED-B907-440C-8096-1FBA56E87231"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cellinx:cellinx_nvt_-_ip_ptz_camera:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "01ADE992-8EE9-4339-8EE8-114A67B4F2D7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cna@cyber.gov.il"
}