Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-59166
HistoryMay 19, 2022 - 12:00 a.m.

Fidelis Network Deception Command Injection Vulnerability (CNVD-2022-59166)

2022-05-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
fidelis network deception
command injection
vulnerability
fidelis usa
inc.
update checkfile
system commands
http requests

EPSS

0.001

Percentile

41.5%

Fidelis Network Deception is a security product from Fidelis USA, Inc. A command injection vulnerability exists in versions prior to Fidelis Network Deception 9.4.5, which stems from the filename parameter of CommandPost when using the update_checkfile value. Command injection exists, and an attacker can use this vulnerability to execute system commands via special HTTP requests.

EPSS

0.001

Percentile

41.5%

Related for CNVD-2022-59166