PT-2022-19229 · Settings · Settings
Published
2022-05-03
·
Updated
2022-05-11
·
CVE-2022-28781
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Settings versions prior to SMR-May-2022 Release 1
Description
The issue is related to improper input validation, which allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.
Recommendations
For versions prior to SMR-May-2022 Release 1, update to SMR-May-2022 Release 1 or later to add proper validation logic and prevent arbitrary activity launch with system privilege.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Settings