PT-2022-14874 · Mmp+2 · Mmp+2

Noam Moshe

·

Published

2022-02-18

·

Updated

2022-02-26

·

CVE-2022-21141

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MMP versions prior to 1.0.3 PTP C-series versions prior to 2.8.6.1 PTMP C-series versions prior to 2.5.4.1 A5x versions prior to 2.5.4.1
Description The issue concerns improper authorization checks on multiple API functions, allowing an attacker to gain access to these functions. This can lead to remote code execution, creation of a denial-of-service condition, and obtaining sensitive information.
Recommendations For MMP versions prior to 1.0.3, update to version 1.0.3 or later. For PTP C-series versions prior to 2.8.6.1, update to version 2.8.6.1 or later. For PTMP C-series versions prior to 2.5.4.1, update to version 2.5.4.1 or later. For A5x versions prior to 2.5.4.1, update to version 2.5.4.1 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21141

Affected Products

A5X
Mmp
Ptmp C-Series