← Back to CVE List
Vulnerability Intelligence Report
Authenticated Command Injection to RCE

CVE-2022-25619

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.

No Active Exploit Signals
CVSS Base Score
3.8
LOW
Exploitability:0.4
Impact Score:3.4
EPSS Probability:0.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-77 ↗CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
Profelis IT Consultancy SambaBox 4.0 <= 4.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.321%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityProfelis IT Consultancy · Vendor · Türkiye
Reserved2022-02-21T00:00:00
Published2022-03-30T14:55:17
Last Updated2024-08-03T04:42:50

LINK COPIED TO CLIPBOARD