ZeroHour

CVE-2022-1361

CVSS 3.1
7.5 high
EPSS
<1%p58
Published
()
Modified
Description

The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices.

Vendors
cambiumnetworks
Products
cnmaestro
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.