7.5

CVE-2022-30624

Chcnav - P5E GNSS Authentication bypass admin password reset

Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ChcnavP5e Gnss Firmware Version4.1
   ChcnavP5e Gnss Version-
ChcnavP5e Gnss Firmware Version4.2
   ChcnavP5e Gnss Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.202
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
cna@cyber.gov.il 6.8 2.5 3.7
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://www.gov.il/en/Departments/faq/cve_advisories
Third Party Advisory