5
CVSSv2

CVE-2022-1359

Published: 17/05/2022 Updated: 06/06/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an malicious user to write any data to any file in the server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cambiumnetworks cnmaestro 2.4.2

cambiumnetworks cnmaestro 3.0.0

cambiumnetworks cnmaestro 3.0.3

ICS Advisories

Cambium Networks cnMaestro
Critical Infrastructure Sectors: Information Technology