PT-2022-26105 · Innovaphone · Innovaphone

Dennis Herrmann

·

Published

2022-09-30

·

Updated

2022-10-11

·

CVE-2022-41870

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Innovaphone versions prior to 13r2 Service Release 17
Description The issue allows command injection via a modified service ID during app upload.
Recommendations For versions prior to 13r2 Service Release 17, update to 13r2 Service Release 17 or later to resolve the issue.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-41870

Affected Products

Innovaphone