VulnerabilityModified
CVE-2022-28054
Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.
CRITICAL 9.8EPSS 31.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 31.89% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- vandyke/vshell
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.