The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-060/ |     | 
History
                    Mon, 10 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: CERTVDE
Published: 2023-02-27T14:36:39.448Z
Updated: 2025-03-10T17:46:52.078Z
Reserved: 2022-11-10T09:46:59.080Z
Link: CVE-2022-45140
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-03T14:09:55.436Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-02-27T15:15:11.503
Modified: 2024-11-21T07:28:50.143
Link: CVE-2022-45140
 Redhat
                        Redhat
                    No data.