Skip to content
COOEY

EXPOSURES › CVE-2022-47758

CVE-2022-47758

CRITICAL
DETAIL
SourceNVD · cve Published2023-04-27 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-47758 ↗
⚡ RCE SHAME 50/100 rce

Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.