CVE-2022-3229
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 66.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 66.35% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285, CWE-306
- Affected
- unifiedremote/unified remote
- Source
- cve@rapid7.com
References
- https://github.com/rapid7/metasploit-framework/pull/16989Exploit, Issue Tracking, Patch
- https://github.com/rapid7/metasploit-framework/pull/16989Exploit, Issue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.