CVE-2022-3086

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
02/12/2022
Last modified:
07/11/2023

Description

Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable <br /> to shell escape, which enables local attackers with non-superuser <br /> credentials to gain full, unrestrictive shell access which may allow an <br /> attacker to execute arbitrary code.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:moxa:uc-8580-t-lx_firmware:1.1:*:*:*:*:*:*:*
cpe:2.3:h:moxa:uc-8580-t-lx:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:uc-8580-t-ct-lx_firmware:1.1:*:*:*:*:*:*:*
cpe:2.3:h:moxa:uc-8580-t-ct-lx:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:uc-8580-t-q-lx_firmware:1.1:*:*:*:*:*:*:*
cpe:2.3:h:moxa:uc-8580-t-q-lx:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:uc-8580-t-ct-q-lx_firmware:1.1:*:*:*:*:*:*:*
cpe:2.3:h:moxa:uc-8580-t-ct-q-lx:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:uc-8580-q-lx_firmware:1.1:*:*:*:*:*:*:*
cpe:2.3:h:moxa:uc-8580-q-lx:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:uc-8580-lx_firmware:1.1:*:*:*:*:*:*:*
cpe:2.3:h:moxa:uc-8580-lx:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:uc-8540-lx_firmware:*:*:*:*:*:*:*:* 1.0 (including) 1.2 (including)
cpe:2.3:h:moxa:uc-8540-lx:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:uc-8540-t-ct-lx_firmware:*:*:*:*:*:*:*:* 1.0 (including) 1.2 (including)


References to Advisories, Solutions, and Tools