CVE-2022-41030
Last modified
CVE-2022-41030 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. EPSS estimates a 2.69% chance of exploitation in the next 30 days.
Description
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no wlan filter mac address WORD descript WORD' command template.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siretta | Quartz-Gold Firmware | g5.0.1.5-210720-141020 |
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1613Exploit, Technical Description, Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1613Exploit, Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41030?
How severe is CVE-2022-41030?
How do I fix CVE-2022-41030?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-41025Several stack-based buffer overflow vulnerabilities exist in…7.2
- CVE-2022-41026Several stack-based buffer overflow vulnerabilities exist in…7.2
- CVE-2022-41027Several stack-based buffer overflow vulnerabilities exist in…7.2
- CVE-2022-41028Several stack-based buffer overflow vulnerabilities exist in…7.2
- CVE-2022-41029Several stack-based buffer overflow vulnerabilities exist in…7.2
- CVE-2022-4103The Royal Elementor Addons WordPress plugin before 1.3.56 do…4.3
- CVE-2022-41031Microsoft Word Remote Code Execution Vulnerability7.8
- CVE-2022-41032NuGet Client Elevation of Privilege Vulnerability7.8
- CVE-2022-41033Windows COM+ Event System Service Elevation of Privilege Vul…7.8
- CVE-2022-41034Visual Studio Code Remote Code Execution Vulnerability7.8
- CVE-2022-41035Microsoft Edge (Chromium-based) Spoofing Vulnerability5.3
- CVE-2022-41036Microsoft SharePoint Server Remote Code Execution Vulnerabil…8.8
Are you affected by CVE-2022-41030?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
