VulnerabilityModified
CVE-2022-32572
An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.
HIGH 8.8EPSS 24.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 24.40% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- wwbn/avideo
- Source
- talos-cna@cisco.com
References
- https://github.com/WWBN/AVideo/blob/e04b1cd7062e16564157a82bae389eedd39fa088/updatedb/updateDb.v12.0.sqlThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1548Exploit, Technical Description, Third Party Advisory
- https://github.com/WWBN/AVideo/blob/e04b1cd7062e16564157a82bae389eedd39fa088/updatedb/updateDb.v12.0.sqlThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1548Exploit, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.