CRITICAL
CVE-2022-27518
CVSS
9.8
KEV
Description
Unauthenticated remote arbitrary code execution
Summary dbcve.org
This is a critical unauthenticated remote arbitrary code execution vulnerability with a CVSS score of 9.8, indicating severe risk. An attacker can exploit this flaw remotely without any credentials to execute arbitrary code on the affected system, potentially leading to complete system compromise.
Mitigation
Apply vendor-provided patches or updates immediately, as this is an unauthenticated RCE that can be exploited remotely. Prioritize internet-facing systems and implement network segmentation as a compensating control until patching is complete.
Weakness (CWE)
CWE-664
EPSS Score
6.68%
Probability of exploitation in next 30 days
93.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.