CVE-2022-21143

EUVD-2022-26390
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input on several locations, which may allow an attacker to inject arbitrary commands.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
icscertCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
airspanmimosa_management_platform
𝑥
< 1.0.3
airspanc6x_firmware
𝑥
< 2.8.6.1
airspanc5x_firmware
𝑥
< 2.8.6.1
airspanc5c_firmware
𝑥
< 2.8.6.1
airspana5x_firmware
𝑥
< 2.5.4.1
𝑥
= Vulnerable software versions