7.2
CVE-2022-2334
- EPSS 62.41%
- Veröffentlicht 17.08.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:47
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Softing ≫ Edgeaggregator Version3.1
Softing ≫ Edgeconnector Version3.1
Softing ≫ Opc Ua C++ Software Development Kit Version6
Softing ≫ Secure Integration Server Version1.22
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 62.41% | 0.983 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| ics-cert@hq.dhs.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-427 Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.