8.8

CVE-2022-43553

A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
UiEdgemax Edgerouter Firmware Version < 2.0.9
   UiEdgemax Edgerouter Version-
UiEdgemax Edgerouter Firmware Version2.0.9 Update-
   UiEdgemax Edgerouter Version-
UiEdgemax Edgerouter Firmware Version2.0.9 Updatehotfix1
   UiEdgemax Edgerouter Version-
UiEdgemax Edgerouter Firmware Version2.0.9 Updatehotfix2
   UiEdgemax Edgerouter Version-
UiEdgemax Edgerouter Firmware Version2.0.9 Updatehotfix4
   UiEdgemax Edgerouter Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.45% 0.926
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-250 Execution with Unnecessary Privileges

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.