← Voltar para CVEs
CVE-2022-40022
CRITICAL9.8
Descricao
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado2/13/2023
Ultima modificacao3/21/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
microchip:syncserver_s650microchip:syncserver_s650_firmware
Fraquezas (CWE)
CWE-77CWE-77
Referencias
http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html(cve@mitre.org)
https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650(cve@mitre.org)
https://www.securifera.com/advisories/CVE-2022-40022/(cve@mitre.org)
http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&id=5&gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcB(af854a3a-2127-422b-91ae-364da2661108)
https://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url=(af854a3a-2127-422b-91ae-364da2661108)
https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650(af854a3a-2127-422b-91ae-364da2661108)
https://www.securifera.com/advisories/CVE-2022-40022/(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.