PT-2022-27575 · Telos Alliance · Telos Alliance Omnia Mpx Node

Published

2022-12-02

·

Updated

2023-02-01

·

CVE-2022-45562

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Telos Alliance Omnia MPX Node versions 1.0.0 through 1.4.9
Description The issue allows attackers to manipulate and access system settings using a backdoor account with low privilege. This can lead to changes in hardware settings and the execution of arbitrary commands in vulnerable system functions that typically require high privilege to access.
Recommendations For Telos Alliance Omnia MPX Node versions 1.0.0 through 1.4.9, consider restricting access to system settings and vulnerable system functions to minimize the risk of exploitation. As a temporary workaround, limit the use of backdoor accounts and ensure that all accounts have appropriate privilege settings. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45562

Affected Products

Telos Alliance Omnia Mpx Node