S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-36642 Scanner

CVE-2022-36642 scanner - Path Traversal vulnerability in Telos Alliance Omnia MPX Node

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
6.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-36642
9.8
CVSS

A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 14, 2026View on NVD →
Detail

Telos Alliance Omnia MPX Node is an audio processing and distribution system that features a comprehensive web interface for remote administration and monitoring. It is designed to provide radio broadcasters with a high-quality, reliable signal processing and transmission solution. The system enables broadcasters to manage their audio signals with ease and efficiency, with features like automatic gain control, multiband limiting, and stereo enhancement.

The CVE-2022-36642 vulnerability discovered in Telos Alliance Omnia MPX Node can lead to a local file disclosure (LFD) attack that gives cybercriminals unauthorized access to user credentials. This vulnerability is located in /appConfig/userDB.json, which stores sensitive user data in plaintext format. Attackers who exploit this vulnerability can easily retrieve this data and gain high-privileged access to the control panel with minimal effort.

When exploited, this vulnerability can lead to catastrophic security breaches that compromise critical business operations, costing a company millions of dollars. Attackers can use the compromised usernames and passwords to gain unauthorized access to the control panel, enabling them to execute arbitrary code, modify critical system configurations, and exfiltrate sensitive data.

Thanks to the advanced features provided by s4e.io, users of the Telos Alliance Omnia MPX Node and other digital assets can easily and quickly learn about vulnerabilities in their systems. s4e.io offers comprehensive security assessments, vulnerability scanning, and penetration testing to help users identify and mitigate potential cyber threats. With their expert guidance and proactive security measures, users can keep their digital assets secure and protected from the latest cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that users take the following precautions:

  • Avoid exposing the system to the internet
  • Install the latest security patches and updates regularly
  • Implement strong user authentication mechanisms, such as two-factor authentication
  • Utilize cryptographic methods such as encryption and hashing to protect sensitive data
  • Conduct regular penetration testing and risk assessments to identify and mitigate potential security weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.