LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-29303: SolarView Compact Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 13, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 3, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-29303 to its Known Exploited Vulnerabilities catalog on Jul 13, 2023, with a federal patch deadline of Aug 3, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.

CVE-2022-29303 is a command injection vulnerability in SolarView Compact. It arises from improper validation of input values on the send test mail console of the product's web server. An attacker who can reach that interface may be able to run operating-system commands on the device, which can lead to full compromise of the appliance and any systems it can reach. Because the product is typically network-connected and may sit in operational or monitoring environments, successful exploitation can give an attacker a foothold for further movement or data access. Confirm all product and version details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-78 (OS Command Injection). The send test mail console accepts input that is not properly sanitized before it is passed to a system command. An attacker who can interact with the web server can supply specially crafted values that cause the underlying operating system to execute unintended commands with the privileges of the web-server process. No further exploit mechanics are required to understand the risk: any unauthenticated or weakly authenticated access to that console feature is enough to attempt abuse. Exact request formats and payloads must be confirmed against the vendor advisory; do not rely on third-party descriptions alone.

Am I affected? How to find it in your systems

SolarView Compact is a networked appliance that exposes a web server. Inventory efforts should focus on any devices identified as SolarView Compact, typically found in industrial monitoring, energy, or facility-management networks. Practical steps include:

If the product is present and the version is not confirmed as patched, treat the device as vulnerable until the vendor advisory is consulted.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2022-29303. Follow the installation instructions published by the vendor exactly; if no update is available for the installed model or firmware branch, discontinue use of the product as directed by CISA. After patching:

Document the change and retain evidence of the update for audit purposes.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures do not eliminate the vulnerability; they only lower the probability of successful exploitation until the permanent fix is installed.

If your data may have been exposed

Command-injection flaws of this class are frequently used to establish persistence and move laterally, so any device that was reachable while unpatched should be treated as potentially compromised. Review logs for signs of exploitation, isolate the appliance, and perform a forensic examination if suspicious activity is found. Known ransomware use of this specific CVE is not documented, yet the general risk of data exposure remains. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether credentials or other information associated with the environment have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSolarView · Compact
WeaknessCWE-78
Added to CISA KEVJul 13, 2023
Federal patch deadlineAug 3, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities