PT-2022-23526 · Telos Alliance · Telos Alliance Omnia Mpx Node
Published
2022-09-02
·
Updated
2022-09-27
·
CVE-2022-36642
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Telos Alliance Omnia MPX Node versions 1.0.0 through 1.5.0+r1
Description
A local file disclosure issue in the
/appConfig/userDB.json file allows attackers to access user credentials, potentially gaining initial access to the control panel with high privileges due to the cleartext storage of sensitive information. This vulnerability can also be exploited to escalate privileges to root and execute arbitrary commands.Recommendations
For versions 1.0.0 through 1.4.9, update to a version later than 1.4.9 to mitigate the risk of local file disclosure and privilege escalation.
For version 1.5.0+r1, consider restricting access to the
/appConfig/userDB.json file until a patch is available.
As a temporary workaround, consider disabling the use of the /appConfig/userDB.json file to minimize the risk of exploitation.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telos Alliance Omnia Mpx Node