Record summary

CVE-2022-40022 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 21, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

MetasploitSymmetricom SyncServer Unauthenticated Remote Command ExecutionMetasploit exploitby Justin Fatuch Apt4hax +2 moreNot analyzed1 file

Ruby

Metasploit

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALSymmetricom SyncServer Unauthenticated - Remote Command ExecutionCVSS 9.8

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device.

Remediation

Apply the latest security patches or firmware updates provided by the vendor to mitigate this vulnerability.

WeaknessesCWE-77
AuthorsDhiyaneshDK, mielverkerken
Template tagscvecve2022packetstormsyncserverrceunauthmicrochipvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:h:microchip:syncserver_s650:-:*:*:*:*:*:*:*
Shodan: html:"Symmetricom SyncServer"

Source: ProjectDiscovery

References

6