Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-59173
HistoryMay 19, 2022 - 12:00 a.m.

Fidelis Network Deception命令注入漏洞

2022-05-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
fidelis network deception
command injection
vulnerability
data loss
threat detection
traffic anomalies
commandpost
system commands
http requests
security product
fidelis usa

EPSS

0.001

Percentile

41.5%

Fidelis Network Deception is a security product from Fidelis USA. used to detect threats and prevent data loss, with features such as detecting malicious behavior, identifying traffic anomalies, and automatically responding to advanced threats.A command injection vulnerability exists in versions prior to Fidelis Network and Deception 9.4.5, which stems from the presence of the feed parameter of CommandPost when using the feed_comm_test value Command injection, an attacker can use this vulnerability to execute system commands via special HTTP requests.

EPSS

0.001

Percentile

41.5%

Related for CNVD-2022-59173