CVE-2022-3086

moderate-risk
Published 2022-12-02

Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code.

Do I need to act?

-
0.12% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.1/10 High
LOCAL / LOW complexity

Affected Products (20)

Uc-8210-T-Lx-S Firmware
Uc-8220-T-Lx Firmware
Uc-8220-T-Lx-Us-S Firmware
Uc-8220-T-Lx-Eu-S Firmware
Uc-8220-T-Lx-Ap-S Firmware
Uc-8112A-Me-T-Lx Firmware
Uc-8112A-Me-T-Lx Firmware
Uc-8131-Lx Firmware
Uc-8131-Lx Firmware
Uc-8132-Lx Firmware
Uc-8132-Lx Firmware
Uc-8162-Lx Firmware
Uc-8162-Lx Firmware
Uc-8112-Lx Firmware
Uc-8112-Lx Firmware
Uc-5101-Lx Firmware
Uc-5101-T-Lx Firmware
Uc-5102-Lx Firmware
Uc-5102-T-Lx Firmware
Uc-5111-Lx Firmware

Affected Vendors

49
/ 100
moderate-risk
Severity 22/34 · High
Exploitability 1/34 · Minimal
Exposure 26/34 · High