CVE-2022-45562

HIGH

Telos Alliance Omnia MPX Node 1.0.0-1.4.9 - Incorrect Default Permissions

Title source: llm
STIX 2.1

Description

Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0100
EPSS Percentile 58.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (1)
telosalliance/omnia_mpx_node_firmware 1.0.0 - 1.4.9
Published Dec 02, 2022
Tracked Since Feb 18, 2026