CVE-2022-1399 - CVE House
Back to Database
Status published Critical CVE-2022-1399

Remote code execution in scheduled tasks component

Vulnerability Description

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-1399

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Ștefania POPESCU - Team Lead, Security @ Bitdefender
  • Ionuț LALU - Security Engineer @ Bitdefender
  • Cristian BUZA - Security Engineer @ Bitdefender
  • Alexandru LAZĂR - Security Researcher @ Bitdefender

Affected Vendor

Affected Software

CMDB
Vulnerable Versions:
unspecified

Timeline

Official Publish: August 16th, 2022
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)