CVE-2022-40022
microchip syncserver_s650_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2022-40022 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 13, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
syncserver_s650_firmwareBrowse microchip / syncserver_s650_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
MetasploitSymmetricom SyncServer Unauthenticated Remote Command ExecutionMetasploit exploitby Justin Fatuch Apt4hax +2 moreNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALSymmetricom SyncServer Unauthenticated - Remote Command ExecutionCVSS 9.8
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device.
Remediation
Apply the latest security patches or firmware updates provided by the vendor to mitigate this vulnerability.
Source: ProjectDiscovery