CVE-2022-28054
Published May 2, 2022
·Updated
Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.
Affected Software
2 affected components
VanDyke VShell<4.6.3
Microsoft Windows
Event History
May 2, 2022
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28054?
CVE-2022-28054 has been classified as critical due to improper sanitization allowing arbitrary code execution.
2
How do I fix CVE-2022-28054?
To mitigate CVE-2022-28054, upgrade VShell to version 4.6.3 or later, which addresses the vulnerability.
3
What software is affected by CVE-2022-28054?
CVE-2022-28054 affects VanDyke Software VShell for Windows up to version 4.6.2.
4
Can CVE-2022-28054 be exploited remotely?
Yes, CVE-2022-28054 can be exploited remotely through crafted trigger action scripts.
5
What are the potential impacts of CVE-2022-28054?
The potential impacts of CVE-2022-28054 include unauthorized access and execution of arbitrary code on affected systems.