CVE-2022-45188
High
|7.8No Exploit
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to execute malicious code remotely, potentially gaining full control over affected systems like FreeBSD, which is used in TrueNAS. It occurs when a specially crafted .appl file is processed, making it crucial for systems running vulnerable versions of Netatalk to be updated or secured.
Technical Description
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
CVSS Vector Analysis
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$2,684($1K-$5K)
Vendor Response
Grade FPatched in 1189 days
Quick Information
Published
Nov 12, 2022
over 3 years ago
Last Modified
Feb 13, 2026
7 days ago
Vendor
netatalk
Product
netatalk