CVE-2022-31795
9.8
CRITICAL · CVSS 3.1 · EPSS 3.1% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and inject special characters such as semicolons, backticks, or command-substitution sequences in order to force the application to execute arbitrary commands.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.11% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-06-20 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| fujitsu | eternus cs8000 |
| fujitsu | eternus cs8000 firmware |
References
- https://cwe.mitre.org/data/definitions/78.html
- https://research.nccgroup.com/2022/05/27/technical-advisory-fujitsu-centricstor-control-center-v8-1-unauthenticated-command-injection/
- https://support.ts.fujitsu.com/ProductSecurity/content/Fujitsu-PSIRT-PSS-IS-2022-050316-Security-Notice-SF.pdf
- https://cwe.mitre.org/data/definitions/78.html
- https://research.nccgroup.com/2022/05/27/technical-advisory-fujitsu-centricstor-control-center-v8-1-unauthenticated-command-injection/
- https://support.ts.fujitsu.com/ProductSecurity/content/Fujitsu-PSIRT-PSS-IS-2022-050316-Security-Notice-SF.pdf
→ the Explorer · watch your stack · NVD