Command Injection Vulnerabilities in LibreNMS by LibreNMS
CVE-2022-29712

9.8CRITICAL

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
2 June 2022

What is CVE-2022-29712?

LibreNMS version 22.3.0 has been identified to have multiple command injection vulnerabilities that can be exploited through parameters such as service_ip, hostname, and service_param. This flaw allows attackers to execute arbitrary commands on the server, potentially leading to unauthorized access or system compromise. It is critical for users to patch their installations to mitigate the risk associated with these vulnerabilities.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.