« Volver al listado

CVE-2022-34869

Estado: ModificadaAlta (8.8)—

Undocumented hidden command that can be executed from the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to execute an arbitrary OS command.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-34869",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Allied Telesis K.K.",
          "product": "CentreCOM AR260S V2",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to Ver.3.3.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-08T08:15:08.007",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN45473612/index.html",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.allied-telesis.co.jp/support/list/faq/vuls/20220829.html",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN45473612/index.html",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.allied-telesis.co.jp/support/list/faq/vuls/20220829.html",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Undocumented hidden command that can be executed from the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to execute an arbitrary OS command."
    },
    {
      "lang": "es",
      "value": "Un comando oculto no documentado que puede ser ejecutado desde la función telnet de las versiones de firmware CentreCOM AR260S versiones V2 anteriores a la versión 3.3.7,, permite a un atacante remoto autenticado ejecutar un comando arbitrario del Sistema Operativo"
    }
  ],
  "lastModified": "2026-06-17T04:51:04.250",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:allied-telesis:centrecom_ar260s_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "597F44F8-3F9F-4E08-A93E-F06F4DD43517",
              "versionEndExcluding": "3.3.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:allied-telesis:centrecom_ar260s:v2:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0EEAA754-161E-4FF2-8C17-6B1E78E6C748"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}