Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-27903

An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.058
EPSS Ranking 90.2%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2022-27903
  • Eve-Ng » Eve-Ng » Version: N/A
    cpe:2.3:a:eve-ng:eve-ng:-
  • Eve-Ng » Eve-Ng » Version: 2.0.3-112
    cpe:2.3:a:eve-ng:eve-ng:2.0.3-112
  • Eve-Ng » Eve-Ng » Version: 4.0.1-65
    cpe:2.3:a:eve-ng:eve-ng:4.0.1-65


Contact Us

Shodan ® - All rights reserved