Vulnerability Description
Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wazuh | Wazuh | >= 3.6.1, <= 3.13.5 |
Related Weaknesses (CWE)
References
- https://github.com/wazuh/wazuh/pull/14801PatchThird Party Advisory
- https://github.com/wazuh/wazuh/pull/14801PatchThird Party Advisory
FAQ
What is CVE-2022-40497?
CVE-2022-40497 is a vulnerability with a CVSS score of 8.8 (HIGH). Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.
How severe is CVE-2022-40497?
CVE-2022-40497 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40497?
Check the references section above for vendor advisories and patch information. Affected products include: Wazuh Wazuh.