CVE-2022-36642
Summary
| CVE | CVE-2022-36642 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-02 22:15:00 UTC |
| Updated | 2022-09-27 15:40:00 UTC |
| Description | A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Telosalliance | Omnia Mpx Node | - | All | All | All |
| Operating System | Telosalliance | Omnia Mpx Node Firmware | All | All | All | All |
| Operating System | Telosalliance | Omnia Mpx Node Firmware | 1.5.0 | - | All | All |
| Operating System | Telosalliance | Omnia Mpx Node Firmware | 1.5.0 | r1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Omnia Node MPX Auth Bypass via LFD - Cyber Guy's Blog | MISC | cyber-guy.gitbook.io | |
| Omnia MPX 1.5.0+r1 - Path Traversal - Hardware remote Exploit | MISC | www.exploit-db.com | |
| Omnia MPX Node | MISC | www.telosalliance.com | |
| Update your browser to use Google Drive, Docs, Sheets, Sites, Slides, and Forms - Google Drive Help | MISC | drive.google.com | |
| Bypassing MPX Node Authentication - Firmware analysis - Cyber Guy's Blog | MISC | cyber-guy.gitbook.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.