VDB

CVE-2022-36633

CVE-2022-36633 PUBLISHED

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

EPSS 30.29% · 96.8th percentile

Risk Scores

EPSS Score
30.29%
96.8th percentile

Affected Products

VendorProductVersions
github.comgravitational/teleport0, 10.0.0, 9.0.0
n/an/an/a
goteleportteleport0

Timeline

  • Aug 23, 2022 PoC Published
  • Aug 24, 2022 CVE Published
  • Aug 25, 2022 EPSS Score
  • Sep 1, 2022 EPSS Score
  • Sep 23, 2022 PoC Published
  • Nov 15, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Aug 31, 2023 EPSS Score
  • Mar 3, 2024 EPSS Score
  • Mar 31, 2024 EPSS Score
  • Apr 14, 2024 EPSS Score
  • Apr 28, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›