CVE-2022-0997
Summary
| CVE | CVE-2022-0997 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-17 20:15:00 UTC |
| Updated | 2022-05-26 01:23:00 UTC |
| Description | Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which could result in arbitrary commands being run as root upon subsequent logon by a root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fidelissecurity | Deception | All | All | All | All |
| Application | Fidelissecurity | Network | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security check | CONFIRM | fidelissecurity.zendesk.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Henry Reed, The Aerospace Corporation
There are currently no legacy QID mappings associated with this CVE.