CVE-2022-40022

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:microchip:syncserver_s650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:microchip:syncserver_s650:-:*:*:*:*:*:*:*

History

14 Jun 2023, 07:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html -

23 Feb 2023, 05:08

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:o:microchip:syncserver_s650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:microchip:syncserver_s650:-:*:*:*:*:*:*:*
First Time Microchip
Microchip syncserver S650
Microchip syncserver S650 Firmware
References (MISC) https://www.securifera.com/advisories/CVE-2022-40022/ - (MISC) https://www.securifera.com/advisories/CVE-2022-40022/ - Third Party Advisory
References (MISC) https://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&id=5&gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcB - (MISC) https://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&id=5&gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcB - Product
References (MISC) https://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url= - (MISC) https://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url= - Product
References (MISC) https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650 - (MISC) https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650 - Product

13 Feb 2023, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-13 15:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-40022

Mitre link : CVE-2022-40022

CVE.ORG link : CVE-2022-40022


JSON object : View

Products Affected

microchip

  • syncserver_s650_firmware
  • syncserver_s650
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')