CVE-2022-23121 is a critical remote code execution vulnerability affecting Netatalk, specifically within the parse_entries function due to improper error handling of AppleDouble entries. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on affected installations, including various Debian-based systems. With a CVSS score of 9.8 (CRITICAL), it presents a significant risk due to its network-based attack vector and low attack complexity. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community attention and media coverage, with multiple vendors like Synology, QNAP, and Western Digital issuing warnings and updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.13CPE matchmatch criteria | cpe:2.3:a:netatalk:netatalk:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.