Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-31137
HistoryJul 08, 2022 - 8:15 p.m.

Remote code execution

2022-07-0820:15:00
PRIOn knowledge base
www.prio-n.com
6

9.5 High

AI Score

Confidence

High

0.949 High

EPSS

Percentile

99.3%

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CPENameOperatorVersion
roxy-wilt6.1.1.0

9.5 High

AI Score

Confidence

High

0.949 High

EPSS

Percentile

99.3%