Vulnerability Description
A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admin user, an attacker can send a crafted password in order to execute Linux commands as the root user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kratosdefense | Spectralnet Narrowband Firmware | < 1.7.5 |
| Kratosdefense | Spectralnet Narrowband | - |
Related Weaknesses (CWE)
References
- https://www.kratosdefense.com/-/media/k/pdf/s/sy/os-011-spectralnet-narrowband.pProduct
- https://www.kratosdefense.com/-/media/k/pdf/s/sy/os-011-spectralnet-narrowband.pProduct
FAQ
What is CVE-2022-38156?
CVE-2022-38156 is a vulnerability with a CVSS score of 7.2 (HIGH). A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admin user, an attacker can send a crafted password in ...
How severe is CVE-2022-38156?
CVE-2022-38156 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38156?
Check the references section above for vendor advisories and patch information. Affected products include: Kratosdefense Spectralnet Narrowband Firmware, Kratosdefense Spectralnet Narrowband.