CVE-2022-45562
Summary
| CVE | CVE-2022-45562 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-02 03:15:00 UTC |
| Updated | 2023-02-01 15:15:00 UTC |
| Description | Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Telos | Omnia Mpx Node | - | All | All | All |
| Operating System | Telos | Omnia Mpx Node Firmware | All | All | All | All |
| Hardware | Telosalliance | Omnia Mpx Node | - | All | All | All |
| Operating System | Telosalliance | Omnia Mpx Node Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2022-45562 - Cyber Guy's Blog | MISC | cyber-guy.gitbook.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.