VYPR
High severity7.1NVD Advisory· Published May 17, 2022· Updated Jun 17, 2026

CVE-2022-1356

CVE-2022-1356

Description

cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user scripts outside allowed commands.

Affected products

5
  • Cambiumnetworks/cnMaestrollm-fuzzy4 versions
    (expand)+ 3 more
    • (no CPE)
    • cpe:2.3:o:cambiumnetworks:cnmaestro:2.4.2:*:*:*:on_premises:*:*:*
    • cpe:2.3:o:cambiumnetworks:cnmaestro:3.0.0:*:*:*:on_premises:*:*:*
    • cpe:2.3:o:cambiumnetworks:cnmaestro:3.0.3:*:*:*:on_premises:*:*:*
  • Cambium Networks/cnMaestrov5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.