CVE Database
/

CVE-2022-37108

Back to search

CVE-2022-37108

Published: Sep 7, 2022

Modified: Aug 3, 2024

PUBLISHED

CVSS v3.1

8.7

HIGH

Description

An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permission to execute arbitrary code on remote ingesters by appending arbitrary text to text files that are executed by the system, such as users' crontab files. The patch for this was present in SNYPR version 6.4 Jun 2022 R3_[06170871], but may have been introduced sooner.

VendorProductVersions

n/a

n/a

affected
n/a

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AC:L/AV:N/A:H/C:N/I:H/PR:H/S:C/UI:N

Attack Complexity

Low

Attack Vector

Network

Availability

High

Confidentiality

None

Integrity

High

Privileges Required

High

Scope

Changed

User Interaction

None

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now