CVE-2022-43326

CVSS V2 None CVSS V3 None
Description
An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.
Overview
  • CVE ID
  • CVE-2022-43326
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-11-29T05:15:11
  • Last Modified Date
  • 2023-02-01T15:44:53
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:telos:alliance_omnia_mpx_node_firmware:1.1.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:telos:alliance_omnia_mpx_node_firmware:1.3.35:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:telos:alliance_omnia_mpx_node_firmware:1.3.37:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:telos:alliance_omnia_mpx_node:-:*:*:*:*:*:*:* 0 OR
References
Reference URL Reference Tags
https://cyber-guy.gitbook.io/cyber-guys-blog/pocs/cve-2022-43326 Exploit Third Party Advisory
History
Created Old Value New Value Data Type Notes
2022-12-07 18:05:28 Added to TrackCVE
2022-12-18 04:33:51 2022-11-29T05:15:11.503 2022-11-29T05:15:11 CVE Published Date updated
2022-12-18 04:33:51 2022-12-02T15:11:44 CVE Modified Date updated
2023-02-01 17:14:05 2023-02-01T15:44:53 CVE Modified Date updated
2023-02-01 17:14:05 Undergoing Analysis Analyzed Vulnerability Status updated