HIGH · 8.8

CVE-2022-45701

Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

Vulnerability Description

Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CommscopeArris Tg2482A Firmware<= 9.1.103
CommscopeArris Tg2482A-
CommscopeArris Tg2492 Firmware<= 9.1.103
CommscopeArris Tg2492-
CommscopeArris Sbg10 Firmware<= 9.1.103
CommscopeArris Sbg10-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-45701?

CVE-2022-45701 is a vulnerability with a CVSS score of 8.8 (HIGH). Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

How severe is CVE-2022-45701?

CVE-2022-45701 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-45701?

Check the references section above for vendor advisories and patch information. Affected products include: Commscope Arris Tg2482A Firmware, Commscope Arris Tg2482A, Commscope Arris Tg2492 Firmware, Commscope Arris Tg2492, Commscope Arris Sbg10 Firmware.