July 13, 2023 · Applied Cybernetics Group
CVE-2022-29303 — SolarView Compact
SolarView Compact Command Injection Vulnerability
- Added to KEV
2023-07-13- Federal due date
2023-08-03- Vendor
- SolarView
- Product
- Compact
- EPSS
- 99.9th percentile (score 0.980, as of
2026-07-13) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- ATT&CK
- T1059 , T1496 , T1505 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-29303
CISA short description
SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.