The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cert.vde.com/en/advisories/VDE-2022-060/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: CERTVDE
Published: 2023-02-27T14:36:39.448Z
Updated: 2024-08-03T14:09:55.436Z
Reserved: 2022-11-10T09:46:59.080Z
Link: CVE-2022-45140
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-02-27T15:15:11.503
Modified: 2024-11-21T07:28:50.143
Link: CVE-2022-45140
Redhat
No data.