VDB

CVE-2022-29516

CVE-2022-29516 PUBLISHED CVSS 10 CRITICAL

FUJITSU Network IPCOM provided by FUJITSU LIMITED is an integrated network appliance. Operation management interface used to operate FUJITSU Network IPCOM contains multiple vulnerabilities listed below. * OS command injection in the web console (CWE-78) - CVE-2022-29516 * Buffer overflow in the Command Line Interface (CWE-120) - CVE-2020-10188 FUJITSU LIMITED reported these vulnerabilities to IPA to notify users of its solution through JVN. JPCERT/CC and FUJITSU LIMITED coordinated under the Information Security Early Warning Partnership.

EPSS 1.90% · 83.6th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
1.90%
83.6th percentile

Affected Products

VendorProductVersions
FUJITSUIPCOM EX2 series
FUJITSUIPCOM VA2/VE1 series
FUJITSUIPCOM VE2 series
FUJITSUIPCOM EX series

Timeline

  • May 18, 2022 CVE Published
  • May 18, 2022 PoC Published
  • May 19, 2022 EPSS Score
  • Jul 7, 2022 EPSS Score
  • Aug 26, 2022 EPSS Score
  • Dec 2, 2022 EPSS Score
  • Jan 20, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 10, 2023 EPSS Score
  • Apr 28, 2023 EPSS Score
  • Aug 4, 2023 EPSS Score
  • Sep 22, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›