CVE-2022-40022
9.8
CRITICAL · CVSS 3.1 · EPSS 92.5% (pctl 100)
Patch early
EPSS 92.5% — above the 10% action threshold.
Description
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 92.47% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-02-13 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| microchip | syncserver s650 |
| microchip | syncserver s650 firmware |
References
- http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html
- https://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&id=5&gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcB
- https://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url=
- https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650
- https://www.securifera.com/advisories/CVE-2022-40022/
- http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html
- https://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&id=5&gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcB
- https://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url=
- https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650
- https://www.securifera.com/advisories/CVE-2022-40022/
→ the Explorer · watch your stack · NVD