PT-2022-27575 · Telos Alliance · Telos Alliance Omnia Mpx Node
Published
2022-12-02
·
Updated
2023-02-01
·
CVE-2022-45562
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Telos Alliance Omnia MPX Node versions 1.0.0 through 1.4.9
Description
The issue allows attackers to manipulate and access system settings using a backdoor account with low privilege. This can lead to changes in hardware settings and the execution of arbitrary commands in vulnerable system functions that typically require high privilege to access.
Recommendations
For Telos Alliance Omnia MPX Node versions 1.0.0 through 1.4.9, consider restricting access to system settings and vulnerable system functions to minimize the risk of exploitation. As a temporary workaround, limit the use of backdoor accounts and ensure that all accounts have appropriate privilege settings. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telos Alliance Omnia Mpx Node