Vulnerability CVE-2022-25152


Published: 2022-06-09

Description:
The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any version prior to 6.35.37347.20040, a malicious actor (with a valid session token) can create a procedure, bypass approval, and execute the procedure. This results in the ability for any user with a valid session token to perform arbitrary code execution and full system take-over on all agents.

Type:

NVD-CWE-noinfo

CVSS2 => (AV:N/AC:L/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9/10
10/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Itarian -> Saas service desk 
Itarian -> On-premise 

 References:
https://csirt.divd.nl/DIVD-2021-00037
https://csirt.divd.nl/CVE-2022-25152

Copyright 2024, cxsecurity.com

 

Back to Top