CVE-2022-1517

CRITICAL

LRM - RCE

Title source: llm
STIX 2.1

Description

LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on the affected produc. An attacker could also exploit this vulnerability to access APIs not intended for general use and interact through the network.

Scores

CVSS v3 10.0
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269 CWE-250
Status published
Products (1)
illumina/local_run_manager 1.3 - 3.1
Published Jun 24, 2022
Tracked Since Feb 18, 2026