← Back to CVEs
CVE-2022-40022
CRITICAL9.8
Description
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published2/13/2023
Last Modified3/21/2025
Sourcenvd
Honeypot Sightings0
Affected Products
microchip:syncserver_s650microchip:syncserver_s650_firmware
Weaknesses (CWE)
CWE-77CWE-77
References
http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html(cve@mitre.org)
https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650(cve@mitre.org)
https://www.securifera.com/advisories/CVE-2022-40022/(cve@mitre.org)
http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&id=5&gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcB(af854a3a-2127-422b-91ae-364da2661108)
https://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url=(af854a3a-2127-422b-91ae-364da2661108)
https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650(af854a3a-2127-422b-91ae-364da2661108)
https://www.securifera.com/advisories/CVE-2022-40022/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.