CRITICAL · 9.3

CVE-2022-47555

Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute commands, create new users with elevated privileges or set up a backdoor.

Vulnerability Description

Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute commands, create new users with elevated privileges or set up a backdoor.

CVSS Score

9.3

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
OrmazabalEkorrci Firmware601j
OrmazabalEkorrci-
OrmazabalEkorccp Firmware601j
OrmazabalEkorccp-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-47555?

CVE-2022-47555 is a vulnerability with a CVSS score of 9.3 (CRITICAL). Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute commands, create new users with elevated privileges or set up a backdoor.

How severe is CVE-2022-47555?

CVE-2022-47555 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-47555?

Check the references section above for vendor advisories and patch information. Affected products include: Ormazabal Ekorrci Firmware, Ormazabal Ekorrci, Ormazabal Ekorccp Firmware, Ormazabal Ekorccp.