9.8
CVE-2022-25329
- EPSS 2.63%
- Published 24.02.2022 03:15:43
- Last modified 21.11.2024 06:52:00
- Source security@trendmicro.com
- Teams watchlist Login
- Open Login
Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.
Data is provided by the National Vulnerability Database (NVD)
Trendmicro ≫ Serverprotect Version5.8 SwPlatformemc
Trendmicro ≫ Serverprotect Version5.8 SwPlatformnetware
Trendmicro ≫ Serverprotect Version5.8 SwPlatformwindows
Trendmicro ≫ Serverprotect For Network Appliance Filer Version5.8
Trendmicro ≫ Serverprotect For Storage Version6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.63% | 0.852 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.