PT-2022-26849 · Telos Alliance · Telos Alliance Omnia Mpx Node

Published

2022-12-02

·

Updated

2022-12-05

·

CVE-2022-43325

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Telos Alliance Omnia MPX Node versions 1.3.* through 1.4.*
Description An unauthenticated command injection issue in the product license validation function allows attackers to execute arbitrary commands via a crafted payload injected into the license input.
Recommendations For versions 1.3.* through 1.4.*, consider disabling the license validation function until a patch is available. Restrict access to the license input to minimize the risk of exploitation. Avoid using the license input in the affected product until the issue is resolved.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-43325

Affected Products

Telos Alliance Omnia Mpx Node