CVE Vulnerabilities

CVE-2022-43553

Published: Dec 05, 2022 | Modified: Dec 08, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.

Affected Software

Name Vendor Start Version End Version
Edgemax_edgerouter_firmware Ui * 2.0.9 (excluding)
Edgemax_edgerouter_firmware Ui 2.0.9 (including) 2.0.9 (including)
Edgemax_edgerouter_firmware Ui 2.0.9-hotfix1 (including) 2.0.9-hotfix1 (including)
Edgemax_edgerouter_firmware Ui 2.0.9-hotfix2 (including) 2.0.9-hotfix2 (including)
Edgemax_edgerouter_firmware Ui 2.0.9-hotfix4 (including) 2.0.9-hotfix4 (including)

References