« Volver al listado

CVE-2022-38394

Estado: ModificadaCrítica (9.8)—

Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-38394",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Allied Telesis K.K.",
          "product": "CentreCOM AR260S V2",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to Ver.3.3.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-08T08:15:08.200",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN45473612/index.html",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.allied-telesis.co.jp/support/list/faq/vuls/20220829.html",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN45473612/index.html",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.allied-telesis.co.jp/support/list/faq/vuls/20220829.html",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command."
    },
    {
      "lang": "es",
      "value": "Un uso de credenciales embebidas para el servidor telnet de las versiones de firmware CentreCOM AR260S V2 anteriores a la versión 3.3.7, permite a un atacante remoto no autenticado ejecutar un comando arbitrario del Sistema Operativo"
    }
  ],
  "lastModified": "2026-06-17T04:56:31.430",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:allied-telesis:centrecom_ar260s_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "597F44F8-3F9F-4E08-A93E-F06F4DD43517",
              "versionEndExcluding": "3.3.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:allied-telesis:centrecom_ar260s:v2:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0EEAA754-161E-4FF2-8C17-6B1E78E6C748"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}