Vulnerability Details CVE-2022-1361
The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.1%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 5.0
Products affected by CVE-2022-1361
-
cpe:2.3:o:cambiumnetworks:cnmaestro:2.4.2
-
cpe:2.3:o:cambiumnetworks:cnmaestro:3.0.0
-
cpe:2.3:o:cambiumnetworks:cnmaestro:3.0.3