« Volver al listado

CVE-2022-36310

Estado: ModificadaAlta (8.8)—

Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue may affect other AirVelocity and AirSpeed models.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-36310",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve-assign@fb.com",
      "affectedData": [
        {
          "vendor": "Airspan",
          "product": "AirVelocity",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "15.18.00.2511",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-16T01:15:13.833",
  "references": [
    {
      "url": "https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-whc6-2989-42xm",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://helpdesk.airspan.com/browse/TRN3-1689",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-whc6-2989-42xm",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://helpdesk.airspan.com/browse/TRN3-1689",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-assign@fb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-242"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue may affect other AirVelocity and AirSpeed models."
    },
    {
      "lang": "es",
      "value": "Airspan AirVelocity 1500 versiones anteriores a 15.18.00.2511, tenía habilitada la función NET-SNMP-EXTEND-MIB en su servicio snmpd, lo que permite a un atacante con capacidad de escritura en SNMP ejecutar comandos como root en el eNodeB. Este problema puede afectar a otros modelos AirVelocity y AirSpeed."
    }
  ],
  "lastModified": "2026-06-17T04:53:12.290",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:airspan:airvelocity_1500_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECF71DBB-8D4C-4A82-8F4B-3907062C1379",
              "versionEndIncluding": "15.18.00.2511",
              "versionStartIncluding": "9.3.0.01249"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:airspan:airvelocity_1500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DB5DBFEA-0C64-4E87-A11E-6C850D4C87CE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve-assign@fb.com"
}