VYPR

Omnia Mpx Node Firmware

by Telosalliance

CVEs (3)

  • CVE-2022-43325CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.

  • CVE-2022-36642CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.10

    A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of…

  • CVE-2022-43326HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.