← volver
CVE-2022-37897

CVE-2022-37897

CVSS 9.8 CRITICALEPSS 1.7%CWE-78
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.8EPSS 1.7%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
03 nov 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →