CVE-2022-36633 is a high-severity command injection vulnerability in Teleport versions up to 9.3.6, allowing for unauthenticated Remote Code Execution (RCE). An attacker can craft a malicious SSH agent installation link containing a URL-encoded bash escape sequence, which, if clicked by a user, can compromise the system. With a CVSS score of 8.8 and a FAUCET Risk Score of 97/100, this vulnerability poses a significant threat due to its network-based attack vector and high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-51019) confirms the existence of public exploit code, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.1.2CPE matchmatch criteria | cpe:2.3:a:goteleport:teleport:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.