9.1
CVE-2022-1525
- EPSS 0.25%
- Veröffentlicht 06.09.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:54
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-602: Client-Side Enforcement of Server-Side Security, which could allow attackers to bypass web access controls by inspecting and modifying the source code of password protected web elements.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cognex ≫ 3d-a1000 Dimensioning System Firmware Version <= 1.0.3\(3354\)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.479 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| ics-cert@hq.dhs.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-602 Client-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.