Vulnerabilities (CVE)

Filtered by vendor Cambiumnetworks Subscribe
Filtered by product Cnmaestro
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1361 1 Cambiumnetworks 1 Cnmaestro 2022-06-07 5.0 MEDIUM 7.5 HIGH
The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices.
CVE-2022-1362 1 Cambiumnetworks 1 Cnmaestro 2022-06-06 9.3 HIGH 7.3 HIGH
The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could abuse this user-controlled data to execute arbitrary commands on the server.
CVE-2022-1359 1 Cambiumnetworks 1 Cnmaestro 2022-06-06 5.0 MEDIUM 7.5 HIGH
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server.
CVE-2022-1358 1 Cambiumnetworks 1 Cnmaestro 2022-06-06 5.0 MEDIUM 7.5 HIGH
The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database.
CVE-2022-1356 1 Cambiumnetworks 1 Cnmaestro 2022-06-06 7.2 HIGH 7.8 HIGH
cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user scripts outside allowed commands.