Umbra Wiki cve cve/CVE-2022-44877
Back to wiki

CVE-2022-44877 — CWP Control Web Panel OS Command Injection Vulnerability

provenance: imported · CVE: CVE-2022-44877 · CWE: CWE-78

CVE-2022-44877: CWP Control Web Panel OS Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project CWP
Product Control Web Panel
Date added 2023-01-17
Due date 2023-02-07
Ransomware campaign use Unknown

Description

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://control-webpanel.com/changelog#1669855527714-450fb335-6194; https://nvd.nist.gov/vuln/detail/CVE-2022-44877

Weakness behind it

CISA records this vulnerability as an instance of CWE-78. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-44877
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →