Lucene search

K
nvd[email protected]NVD:CVE-2022-28373
HistoryJul 14, 2022 - 1:15 p.m.

CVE-2022-28373

2022-07-1413:15:08
CWE-78
web.nvd.nist.gov
1
verizon
5g
home
lvskihp
indoorunit
idu
remote code execution
root
network
json listener
shell metacharacters
lua

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.008

Percentile

82.0%

Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of the crtcrpc JSON listener in /usr/lib/lua/luci/crtc.lua. A remote attacker on the local network can inject shell metacharacters to achieve remote code execution as root.

Affected configurations

Nvd
Node
verizonlvskihp_indoorunit_firmwareMatch3.4.66.162
AND
verizonlvskihp_indoorunitMatch-
VendorProductVersionCPE
verizonlvskihp_indoorunit_firmware3.4.66.162cpe:2.3:o:verizon:lvskihp_indoorunit_firmware:3.4.66.162:*:*:*:*:*:*:*
verizonlvskihp_indoorunit-cpe:2.3:h:verizon:lvskihp_indoorunit:-:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.008

Percentile

82.0%

Related for NVD:CVE-2022-28373