HIGH

CVE-2022-27224

CVSS v3

7.2

HIGH

EPSS Score

13.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-management interface. All three networking tools are affected (Ping, Traceroute, and DNS Lookup) and their respective input fields (ping_address, trace_address, nslookup_address).

Technical details

Published
5/9/2022

Frequently asked questions

What is CVE-2022-27224?

An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-management interface. All three networking tools are affected (Ping, Traceroute, and DNS Lookup) and their respective input fields (ping_address, trace_address, nslookup_address).

Is CVE-2022-27224 actively exploited?

Active exploitation of CVE-2022-27224 has not been confirmed. The EPSS score is 13.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-27224?

CVE-2022-27224 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2022-27224 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.