← Vulnerability feed

Vulnerability record · CVE-2022-40022 · published 13 February 2023

CVE-2022-40022: Microchip SyncServer S650 command injection

Microchip · Syncserver S650 Firmware

Microchip (Microsemi) SyncServer S650 firmware contains a command injection flaw (CWE-77). The CVSS 3.1 score is 9.8 critical with a network vector and no privileges or user interaction required, so an unauthenticated remote attacker can reach it. The record gives no affected version range and only a one-line description, so the exact injection point is not specified here.

9.8 CVSS 3.1 Critical EPSS 92% · top 0.2% CWE-77 · Command injection
9.8CVSS 3.1 base score
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus a very high EPSS score, makes this a top remediation target despite the thin record.

What it is

Microchip (Microsemi) SyncServer S650 firmware contains a command injection flaw (CWE-77). The CVSS 3.1 score is 9.8 critical with a network vector and no privileges or user interaction required, so an unauthenticated remote attacker can reach it. The record gives no affected version range and only a one-line description, so the exact injection point is not specified here.

Impact

An attacker can execute arbitrary commands on the device, giving full compromise of confidentiality, integrity and availability per the CVSS vector. On a network time server this can mean loss of accurate time and a foothold on the network.

Attack surface

Reachable over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). The description does not name the specific interface or parameter, so the exact entry point is unknown from this record.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.92472 (99.82 percentile), indicating very high predicted likelihood. A Packet Storm reference is titled unauthenticated remote command execution, which suggests public exploit material exists.

What to do

  • Apply the vendor fix for SyncServer S650 once Microchip publishes it; the record does not list a patch, so confirm with the vendor.
  • If no patch is available, isolate SyncServer S650 devices from untrusted networks and restrict management access to a dedicated segment.
  • Block or tightly filter network access to the device's management and service ports at the firewall.
  • Monitor vendor advisories and the Securifera advisory for updated remediation guidance.
  • Treat the device as untrusted and rotate any credentials or keys it holds.

Detection

  • Monitor device and network logs for unexpected outbound connections or command execution activity from SyncServer S650 hosts.
  • Alert on anomalous process or shell activity on the appliance where host-level telemetry is available.
  • Watch for scanning or exploit attempts against the device's exposed services from the Securifera and Packet Storm references.
  • Baseline normal management traffic to the device and alert on deviations, since the exact vulnerable endpoint is not documented here.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-40022 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed6.1CVE-2025-59689Libraesva ESG command injection via compressed email attachmentLibraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachme…KEVEPSS 1.9%analysed9.8CVE-2025-10035Fortra GoAnywhere MFT License Servlet deserialization to command injectionThe License Servlet in Fortra GoAnywhere MFT deserializes untrusted data, and an attacker who can present a validly forged license response signature…KEVEPSS 100%analysed8.8CVE-2020-25079D-Link DCS cameras authenticated command injection in ddns_enc.cgiD-Link DCS-2530L (before 1.06.01 Hotfix) and DCS-2670L (through 2.02) contain an authenticated command injection flaw in cgi-bin/ddns_enc.cgi. A user…KEVEPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2022-40022), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.