9.8
CVE-2022-25329
- EPSS 2.69%
- Veröffentlicht 24.02.2022 03:15:43
- Zuletzt bearbeitet 21.11.2024 06:52:00
- Erkennungen
Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform emc
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform netware
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform windows
Trendmicro ≫ Serverprotect For Network Appliance Filer Version 5.8
Trendmicro ≫ Serverprotect For Storage Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.69% | 0.842 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
https://success.trendmicro.com/solution/000290507
https://www.tenable.com/security/research/tra-2022-05