CVE-2022-50925
9.8Prowise · Prowise Reflect
Prowise Reflect version 1.0.9 is vulnerable to remote keystroke injection via an exposed WebSocket on port 8082, allowing unauthenticated attackers to execute arbitrary keyboard commands.
Executive summary
Prowise Reflect version 1.0.9 contains a critical remote keystroke injection vulnerability that enables unauthenticated attackers to execute arbitrary commands on the host system.
Vulnerability
The application fails to properly validate the origin of requests sent to a WebSocket service on port 8082, allowing an unauthenticated remote attacker to inject malicious keystrokes.
Business impact
This vulnerability carries a CVSS score of 9.8, reflecting a critical severity level. Successful exploitation allows an attacker to interact with the host system as if they had physical keyboard access, potentially leading to unauthorized application execution, data exfiltration, or complete system compromise.
Remediation
Immediate Action: Consult the official Prowise support portal for patch availability and apply the latest security updates immediately.
Proactive Monitoring: Monitor network traffic directed toward port 8082 for unauthorized or anomalous WebSocket connection attempts.
Compensating Controls: Restrict network access to port 8082 using host-based firewalls or network access control lists to ensure only authorized management traffic is permitted.
Exploitation status
Public Exploit Available: Yes — an entry exists on ExploitDB.
Analyst recommendation
Given the critical nature of this remote code execution vector, organizations using Prowise Reflect should prioritize mitigation. If a patch is not immediately available, isolating the affected system from untrusted networks is mandatory to prevent unauthorized remote interaction.