Skip to content
COOEY

EXPOSURES › CVE-2022-39197

CVE-2022-39197

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-03-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-39197 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Fortra Cobalt Strike XSS allowed remote code execution

Fortra's Cobalt Strike Teamserver had a Cross-Site Scripting (XSS) vulnerability, enabling attackers to execute code remotely via a malformed username in the Beacon configuration. This was actively exploited, posing a high risk to DIB organizations.

Shame score — Actively exploited, high severity, and allowed remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.