CVE Feed

    Dashboard / CVE / CVE-2022-29539

    CVE-2022-29539

    resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by the software (e.g., concatenate `&|;\r\ commands) and inject arbitrary system commands with the privileges of the application user.

    Published:May 12, 2022
    Last Modified:Nov 21, 2024
    EPS:May 12, 2022
    EPSS Score:0.1719
    CVSS Score:9.8

    Affected Products

    Vendor
    Resi
    Product
    Gemini-net

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High