VEXID-1315332
Published 2022-07-17 23:15:08
Last Modified 2024-11-21 07:04:07
AKA CVE-2022-31208
Summary An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary commands by manipulating the cmd_string URL parameter.
CVSS Score 9
CVSS
Access Vector Local Adjacent Network
Access Complexity Low Medium High
Authentication None Single Multiple
Confidentiality None Partial Complete
Integrity None Partial Complete
Availability None Partial Complete