CVE-2022-2663

ECS: Improper Restriction of Communication Channel to Intended Endpoints (CVE-2022-2663)

Affected

  • Dell/ECS 3.8.1.0..*

Description

A flaw was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and it incorrectly matches on the message. An attacker could exploit this vulnerability to bypass firewall when users are using unencrypted IRC with nf_conntrack_irc configured.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

DellECS
3.8.1.0

Metrics

87.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
none
no public PoC known
3.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2022-09-01 00:00 UTC
CWE-923

Weakness classes (CWE)

  • CWE-923Class

    Improper Restriction of Communication Channel to Intended Endpoints

    The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

    cwe.mitre.org →

References & sources