CVE-2022-23650

7.2 HIGH
Published: February 18, 2022 Modified: May 18, 2026
View on NVD

Description

Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard-coded cryptographic key in the code base which can be exploited to run admin commands on a remote server if the exploiter know the address and username of the admin. This effects the server (netmaker) component, and not clients. This has been patched in Netmaker v0.8.5, v0.9.4, and v0.10.0. There are currently no known workarounds.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/gravitl/netmaker/commit/3d4f44ecfe8be4ca38920556ba3b90502ffb4fee
Source: security-advisories@github.com
Patch Third Party Advisory
https://github.com/gravitl/netmaker/commit/e9bce264719f88c30e252ecc754d08f422f4c080
Source: security-advisories@github.com
Patch Third Party Advisory
https://github.com/gravitl/netmaker/pull/781/commits/1bec97c662670dfdab804343fc42ae4b1d050a87
Source: security-advisories@github.com
Patch Third Party Advisory
https://github.com/gravitl/netmaker/security/advisories/GHSA-86f3-hf24-76q4
Source: security-advisories@github.com
Third Party Advisory
https://github.com/gravitl/netmaker/commit/3d4f44ecfe8be4ca38920556ba3b90502ffb4fee
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
https://github.com/gravitl/netmaker/commit/e9bce264719f88c30e252ecc754d08f422f4c080
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
https://github.com/gravitl/netmaker/pull/781/commits/1bec97c662670dfdab804343fc42ae4b1d050a87
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
https://github.com/gravitl/netmaker/security/advisories/GHSA-86f3-hf24-76q4
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.2 / 10.0
EPSS (Exploit Probability)
1.5%
71th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

netmaker