Vulnerabilities > CVE-2022-1401 - Incorrect Authorization vulnerability in Device42 Cmdb
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Device42 CMDB versions prior to 18.01.00.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |