ID

VAR-202209-2127


CVE

CVE-2022-41870


TITLE

innovaphone AG  of  innovaphone  Command injection vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2022-018049

DESCRIPTION

AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload. innovaphone AG of innovaphone Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. innovaphone AG is an expert in the IP telephony field of German innovaphone AG company that provides personalized and complex business communication solutions. Attackers exploit this vulnerability to modify service IDs and inject commands

Trust: 1.8

sources: NVD: CVE-2022-41870 // JVNDB: JVNDB-2022-018049 // VULHUB: VHN-429146 // VULMON: CVE-2022-41870

AFFECTED PRODUCTS

vendor:innovaphonemodel:innovaphonescope:eqversion:13r2

Trust: 1.0

vendor:innovaphonemodel:innovaphonescope:ltversion:13r2

Trust: 1.0

vendor:innovaphonemodel:innovaphonescope:eqversion:innovaphone firmware 13r2

Trust: 0.8

vendor:innovaphonemodel:innovaphonescope:eqversion: -

Trust: 0.8

vendor:innovaphonemodel:innovaphonescope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-018049 // NVD: CVE-2022-41870

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-41870
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2022-41870
value: HIGH

Trust: 1.0

NVD: CVE-2022-41870
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202209-3165
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2022-41870
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.1

Trust: 2.0

NVD: CVE-2022-41870
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-018049 // CNNVD: CNNVD-202209-3165 // NVD: CVE-2022-41870 // NVD: CVE-2022-41870

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.1

problemtype:Command injection (CWE-77) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-429146 // JVNDB: JVNDB-2022-018049 // NVD: CVE-2022-41870

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202209-3165

TYPE

command injection

Trust: 0.6

sources: CNNVD: CNNVD-202209-3165

PATCH

title:innovaphone AG Fixes for command injection vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=210288

Trust: 0.6

sources: CNNVD: CNNVD-202209-3165

EXTERNAL IDS

db:NVDid:CVE-2022-41870

Trust: 3.4

db:JVNDBid:JVNDB-2022-018049

Trust: 0.8

db:CNNVDid:CNNVD-202209-3165

Trust: 0.7

db:VULHUBid:VHN-429146

Trust: 0.1

db:VULMONid:CVE-2022-41870

Trust: 0.1

sources: VULHUB: VHN-429146 // VULMON: CVE-2022-41870 // JVNDB: JVNDB-2022-018049 // CNNVD: CNNVD-202209-3165 // NVD: CVE-2022-41870

REFERENCES

url:http://wiki.innovaphone.com/index.php?title=reference13r2:release_notes_security

Trust: 2.6

url:https://nvd.nist.gov/vuln/detail/cve-2022-41870

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-41870/

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-429146 // VULMON: CVE-2022-41870 // JVNDB: JVNDB-2022-018049 // CNNVD: CNNVD-202209-3165 // NVD: CVE-2022-41870

SOURCES

db:VULHUBid:VHN-429146
db:VULMONid:CVE-2022-41870
db:JVNDBid:JVNDB-2022-018049
db:CNNVDid:CNNVD-202209-3165
db:NVDid:CVE-2022-41870

LAST UPDATE DATE

2025-05-22T23:07:16.075000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-429146date:2022-10-11T00:00:00
db:VULMONid:CVE-2022-41870date:2022-09-30T00:00:00
db:JVNDBid:JVNDB-2022-018049date:2023-10-18T08:09:00
db:CNNVDid:CNNVD-202209-3165date:2022-10-12T00:00:00
db:NVDid:CVE-2022-41870date:2025-05-20T19:15:48.370

SOURCES RELEASE DATE

db:VULHUBid:VHN-429146date:2022-09-30T00:00:00
db:VULMONid:CVE-2022-41870date:2022-09-30T00:00:00
db:JVNDBid:JVNDB-2022-018049date:2023-10-18T00:00:00
db:CNNVDid:CNNVD-202209-3165date:2022-09-30T00:00:00
db:NVDid:CVE-2022-41870date:2022-09-30T18:15:11.973