CVE-2022-39197
Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 6.1
- EPSS
- 46.4% 백분위 98.7% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2023.04.20
- 공개일
- 2022.09.22
CISA KEV에 등록된 실제 악용 확인 취약점
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
공급사 Fortra
제품 Cobalt Strike
영향 버전 n/a, < 4.7.1
수정 버전 4.7.1
Apply updates per vendor instructions.
조치 기한: 2023.04.20CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE CWE-20, CWE-79
KEV 등록일 2023.03.30
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/; https://nvd.nist.gov/vuln/detail/CVE-2022-39197
EPSS 데이터 기준일 2026.06.27