CVE Published: 06/02/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: rapid7 |
Vendor: Unified Intents AB |
Product: Unified Remote Status : PUBLISHED
CVE-2022-3229 Description
Because the web management interface for Unified Intents\' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker\'s choosing.