SpectralNet Narrowband (NB) versions prior to 1.7.5 contain a bug that can be exploited to result in remote authenticated privilege escalation and code execution. Successful exploitation requires valid login credentials.
← Back to Vulnerability Advisories
CVE-2022-38156
High
CVE-2022-38156: SpectalNet Security Update
Synopsis
SpectalNet Security Update
Overview & Description
Solution & Remediation
Solution
Changing default login credentials and using strong passwords are effective mitigations. The issue is resolved in SpectralNet Narrowband (NB) version 1.7.5 or above.
Fix and Mitigation
Upgrade to SpectralNet Narrowband (NB) version 1.7.5 or above. This product release includes an important security update with a severity rating of “High”. Kratos recommends following industry best practices of changing default login credentials and using strong passwords, which can effectively mitigate risk for prior product releases..