Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-44699

Опубликовано: 13 дек. 2022
Источник: msrc
CVSS3: 5.5
EPSS Низкий

Описание

Azure Network Watcher Agent Security Feature Bypass Vulnerability

FAQ

What is Network Watcher?

Azure Network Watcher provides tools to monitor, diagnose, view metrics, and enable or disable logs for resources in an Azure virtual network. Network Watcher is designed to monitor and repair the network health of IaaS (Infrastructure-as-a-Service) products including Virtual Machines (VM), Virtual Networks, Application Gateways, Load balancers, etc. For more details, please refer to: What is Azure Network Watcher?.

How could an attacker exploit this vulnerability?

An attacker with permissions to perform Run Commands on Linux VMs hosting the Azure Network Watcher VM extension could terminate the ongoing Packet Capture created via Network Watcher. This could result in the loss of the on-going network packet capture data and limit troubleshooting and diagnostic capabilities.

What is Network Watcher Agent?

Azure Network Watcher Agent is a virtual machine (VM) extension required for capturing network traffic on demand and using other advanced monitoring and diagnostics capabilities such as Connection Monitor, Connection Troubleshoot and Packet Capture.

How do I know if I am affected by this vulnerability?

Only customers running a Linux VM that has the Azure Network Watcher VM extension installed are susceptible to this vulnerability.

Обновления

ПродуктСтатьяОбновление
Azure Network Watcher VM Extension

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 38%
0.00159
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

Azure Network Watcher Agent Security Feature Bypass Vulnerability

CVSS3: 5.5
github
больше 2 лет назад

Azure Network Watcher Agent Security Feature Bypass Vulnerability.

CVSS3: 5.5
fstec
больше 2 лет назад

Уязвимость службы мониторинга производительности сети Azure Network Watcher Agent, связанная с ошибками авторизации, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 38%
0.00159
Низкий

5.5 Medium

CVSS3