EXPOSURES › CVE-2022-47758
CVE-2022-47758
CRITICAL
DETAIL
SourceNVD · cve
Published2023-04-27
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-47758 ↗
⚡ RCE
SHAME 50/100
rce
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.