Improper Access Control vulnerability in Device42 CMDB versions prior to 18.01.00 allows unauthorized access to sensitive server files

Improper Access Control vulnerability in Device42 CMDB versions prior to 18.01.00 allows unauthorized access to sensitive server files

CVE-2022-1401 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Device42 CMDB versions prior to 18.01.00.

Learn more about our Cis Benchmark Audit For Server Software.