HIGH🇵🇱 Wersja polska

CVE-2022-36309

CVSS 8.8v3.1pub. 2022-08-16upd. 2024-11-21

Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Airspan Airvelocity 1500

    HW
    Airspan
    all versions
  • Airspan Airvelocity 1500 Firmware

    OS
    Airspan
    9.3.0.01249 – 15.18.00.2511
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-36308CRITICAL9.1PL ✓same product

Airspan AirVelocity 1500 — ujawnienie i niezabezpieczone przechowywanie poświadczeń SNMP

CVE-2022-36310HIGH8.8same product

Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd ...

CVE-2022-36312HIGH8.8same product

Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management ...

CVE-2022-36306MEDIUM6.5same product

An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI...

CVE-2022-36307MEDIUM6.8same product

The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fi...