CVE-2022-40022
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 92%
from disclosure to weapon0 days
Published on NVDFeb 13
metasploitAug 31
VulnCheck+273d
exploitation probability
92%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 1
cve_referencepacketstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.htmlhttps://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&id=5&gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcBhttps://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url=https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650https://www.securifera.com/advisories/CVE-2022-40022/