CVE-2022-0486
Last modified
CVE-2022-0486 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of privileges equivalent to the root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of privileges equivalent to the root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fidelissecurity | Deception | < 9.4.5 |
| Fidelissecurity | Network | < 9.4.5 |
References
- https://fidelissecurity.zendesk.com/hc/en-us/articles/6211730139411Permissions Required, Vendor Advisory
- https://fidelissecurity.zendesk.com/hc/en-us/articles/6211730139411Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-0486?
How severe is CVE-2022-0486?
How do I fix CVE-2022-0486?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-0480A flaw was found in the filelock_init in fs/locks.c function…5.5
- CVE-2022-0481NULL Pointer Dereference in Homebrew mruby prior to 3.2.7.5
- CVE-2022-0482Exposure of Private Personal Information to an Unauthorized …9.1
- CVE-2022-0483Local privilege escalation due to insecure folder permission…7.8
- CVE-2022-0484Lack of validation of URLs causes Mirantis Container Cloud L…8.8
- CVE-2022-0485A flaw was found in the copying tool `nbdcopy` of libnbd. Wh…4.8
- CVE-2022-0487A use-after-free vulnerability was found in rtsx_usb_ms_drv_…5.5
- CVE-2022-0488An issue has been discovered in GitLab CE/EE affecting all v…4.3
- CVE-2022-0489An issue has been discovered in GitLab CE/EE affecting all v…5.7
- CVE-2022-0492A vulnerability was found in the Linux kernel’s cgroup_relea…7.8
- CVE-2022-0493The String locator WordPress plugin before 2.5.0 does not pr…4.9
- CVE-2022-0494A kernel information leak flaw was identified in the scsi_io…4.4
Are you affected by CVE-2022-0486?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
