9.8

CVE-2022-36642

Exploit
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Telosalliance ≫ Omnia Mpx Node Firmware Version >= 1.0.0 < 1.5.0
   Telosalliance ≫ Omnia Mpx Node Version -
Telosalliance ≫ Omnia Mpx Node Firmware Version 1.5.0 Update -
   Telosalliance ≫ Omnia Mpx Node Version -
Telosalliance ≫ Omnia Mpx Node Firmware Version 1.5.0 Update r1
   Telosalliance ≫ Omnia Mpx Node Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.96% 0.951
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://cyber-guy.gitbook.io/cyber-guy/pocs/omnia-node-mpx-auth-bypass-via-lfd
Third Party Advisory
Exploit
https://cyber-guy.gitbook.io/cyber-guys-blog/blogs/bypassing-mpx-node-authentication-firmware-analysis
Third Party Advisory
Exploit
https://drive.google.com/drive/folders/1jm9h8JNmezTt7AbHYRY7gPC4lXGDNklL
Third Party Advisory
Exploit
https://www.exploit-db.com/exploits/50996
Third Party Advisory
Exploit
VDB Entry
https://www.telosalliance.com/radio-processing/audio-interfaces/omnia-mpx-node
Vendor Advisory
Product