Cambiumnetworks
Cambiumnetworks Cnmaestro: vulnerabilidades y CVE
Cambiumnetworks Cnmaestro tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-1362 | Alta (7.3) | 0.80% | — | 17 may 2022 | The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could abuse this user-controlled data to execute arbitrary commands on the… |
| CVE-2022-1361 | Alta (7.5) | 0.95% | — | 17 may 2022 | The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other… |
| CVE-2022-1360 | Crítica (9.8) | 1.9% | — | 17 may 2022 | The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change server configuration settings. |
| CVE-2022-1359 | Alta (7.5) | 0.97% | — | 17 may 2022 | The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters… |
| CVE-2022-1358 | Alta (7.5) | 0.87% | — | 17 may 2022 | The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro… |
| CVE-2022-1357 | Crítica (9.8) | 1.8% | — | 17 may 2022 | The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of validation could allow an attacker to… |
| CVE-2022-1356 | Alta (7.8) | 0.27% | — | 17 may 2022 | cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user… |