peter bassill · operator
$ cve CVE-2022-43325 JSON

CVE-2022-43325

9.8
CRITICAL · CVSS 3.1 · EPSS 6% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.01% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2022-12-02
Last modified2026-06-17

Affected (2)

VendorProduct
telosallianceomnia mpx node
telosallianceomnia mpx node firmware

References

→ the Explorer  ·  watch your stack  ·  NVD