Vulnerability Description
Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard-coded cryptographic key in the code base which can be exploited to run admin commands on a remote server if the exploiter know the address and username of the admin. This effects the server (netmaker) component, and not clients. This has been patched in Netmaker v0.8.5, v0.9.4, and v0.10.0. There are currently no known workarounds.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netmaker | Netmaker | < 0.8.5 |
Related Weaknesses (CWE)
References
- https://github.com/gravitl/netmaker/commit/3d4f44ecfe8be4ca38920556ba3b90502ffb4PatchThird Party Advisory
- https://github.com/gravitl/netmaker/commit/e9bce264719f88c30e252ecc754d08f422f4cPatchThird Party Advisory
- https://github.com/gravitl/netmaker/pull/781/commits/1bec97c662670dfdab804343fc4PatchThird Party Advisory
- https://github.com/gravitl/netmaker/security/advisories/GHSA-86f3-hf24-76q4Third Party Advisory
- https://github.com/gravitl/netmaker/commit/3d4f44ecfe8be4ca38920556ba3b90502ffb4PatchThird Party Advisory
- https://github.com/gravitl/netmaker/commit/e9bce264719f88c30e252ecc754d08f422f4cPatchThird Party Advisory
- https://github.com/gravitl/netmaker/pull/781/commits/1bec97c662670dfdab804343fc4PatchThird Party Advisory
- https://github.com/gravitl/netmaker/security/advisories/GHSA-86f3-hf24-76q4Third Party Advisory
FAQ
What is CVE-2022-23650?
CVE-2022-23650 is a vulnerability with a CVSS score of 7.2 (HIGH). Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard-coded cryptographic key in the code base which can...
How severe is CVE-2022-23650?
CVE-2022-23650 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23650?
Check the references section above for vendor advisories and patch information. Affected products include: Netmaker Netmaker.