9.8

CVE-2022-36642

Exploit
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TelosallianceOmnia Mpx Node Firmware Version >= 1.0.0 < 1.5.0
   TelosallianceOmnia Mpx Node Version-
TelosallianceOmnia Mpx Node Firmware Version1.5.0 Update-
   TelosallianceOmnia Mpx Node Version-
TelosallianceOmnia Mpx Node Firmware Version1.5.0 Updater1
   TelosallianceOmnia Mpx Node Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 70.72% 0.987
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.