Vulnerability record · CVE-2022-3229 · published 6 February 2023
CVE-2022-3229: Unified Remote web management interface missing authentication allows RCE
Unifiedremote · Unified Remote
The web management interface of Unified Intents' Unified Remote does not require authentication. A remote, unauthenticated attacker can use it to change or disable authentication requirements for the Unified Remote protocol, then abuse that now-unauthenticated access to run arbitrary code. This matters because it turns an exposed management interface directly into remote code execution with no credentials needed.
Description
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and public exploit tooling make this an urgent remote code execution risk.
What it is
The web management interface of Unified Intents' Unified Remote does not require authentication. A remote, unauthenticated attacker can use it to change or disable authentication requirements for the Unified Remote protocol, then abuse that now-unauthenticated access to run arbitrary code. This matters because it turns an exposed management interface directly into remote code execution with no credentials needed.
Impact
An attacker gains unauthenticated remote code execution on the host running Unified Remote, with full compromise of confidentiality, integrity and availability. They can also weaken or remove authentication on the Unified Remote protocol itself, widening access for further abuse.
Attack surface
Reachable over the network via the web management interface (CVSS vector AV:N/AC:L/PR:N/UI:N), so no authentication and no user interaction are required. Any host exposing this interface to an untrusted network is directly exposed.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.66354, 99.2nd percentile) and the only references are a Metasploit pull request tagged Exploit and Patch, indicating public exploit tooling exists. No ransomware usage is documented.
What to do
- Apply the vendor fix for the web management interface authentication flaw; the referenced Metasploit PR is tagged Patch, so confirm the current Unified Remote release and update.
- Do not expose the Unified Remote web management interface to untrusted networks; restrict it to localhost or a trusted management VLAN.
- Block or firewall the management interface and Unified Remote protocol ports from external access.
- Enable authentication on the Unified Remote protocol and verify it has not been disabled or altered.
- Audit the host for unauthorized configuration changes and unexpected processes if exposure is suspected.
Detection
- Monitor network access to the Unified Remote web management interface from untrusted sources, especially unauthenticated requests.
- Alert on changes to Unified Remote authentication settings or configuration files.
- Hunt for unexpected child processes spawned by the Unified Remote service.
- Review logs for Metasploit-style exploitation attempts against the management interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/rapid7/metasploit-framework/pull/16989 | ExploitIssue TrackingPatch |
| https://github.com/rapid7/metasploit-framework/pull/16989 | ExploitIssue TrackingPatch |
Track CVE-2022-3229 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-3229), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.