{
	"CVE_data_meta": {
		"ASSIGNER": "cve-assign@fb.com",
		"DATE_ASSIGNED": "2022-07-19",
		"ID": "CVE-2022-36310",
		"STATE": "PUBLIC"
	},
	"affects": {
		"vendor": {
			"vendor_data": [
				{
					"vendor_name": "Airspan",
					"product": {
						"product_data": [
							{
								"product_name": "AirVelocity",
								"version": {
									"version_data": [
										{
											"version_affected": "<",
											"version_value": "15.18.00.2511"
										}
									]
								}
							}
						]
					}
				}
			]
		}
	},
	"data_format": "MITRE",
	"data_type": "CVE",
	"data_version": "4.0",
	"description": {
		"description_data": [
			{
				"lang": "eng",
				"value": "Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue may affect other AirVelocity and AirSpeed models."
			}
		]
	},
	"problemtype": {
		"problemtype_data": [
			{
				"description": [
					{
						"lang": "eng",
						"value": "Use of Inherently Dangerous Function (CWE-242)"
					}
				]
			}
		]
	},
	"references": {
		"reference_data": [
			{
				"refsource": "CONFIRM",
				"name": "https://helpdesk.airspan.com/browse/TRN3-1689",
				"url": "https://helpdesk.airspan.com/browse/TRN3-1689"
			},
			{
				"refsource": "MISC",
				"name": "https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-whc6-2989-42xm",
				"url": "https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-whc6-2989-42xm"
			}
		]
	}
}
