2.3
CVE-2022-23744
- EPSS 0.12%
- Published 07.07.2022 16:15:09
- Last modified 21.11.2024 06:49:13
- Source cve@checkpoint.com
- Teams watchlist Login
- Open Login
Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator.
Data is provided by the National Vulnerability Database (NVD)
Checkpoint ≫ Endpoint Security Versione83
Checkpoint ≫ Endpoint Security Versione84
Checkpoint ≫ Endpoint Security Versione85
Checkpoint ≫ Endpoint Security Versione86.10
Checkpoint ≫ Endpoint Security Versione86.20
Checkpoint ≫ Endpoint Security Versione86.30
Checkpoint ≫ Endpoint Security Versione86.40
Checkpoint ≫ Harmony Endpoint Versione83
Checkpoint ≫ Harmony Endpoint Versione84
Checkpoint ≫ Harmony Endpoint Versione85
Checkpoint ≫ Harmony Endpoint Versione86.10
Checkpoint ≫ Harmony Endpoint Versione86.20
Checkpoint ≫ Harmony Endpoint Versione86.30
Checkpoint ≫ Harmony Endpoint Versione86.40
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.12% | 0.32 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 2.3 | 0.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:P
|
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.