5.7
CVE-2022-30625
- EPSS 0.14%
- Veröffentlicht 18.07.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:03:03
- Quelle cna@cyber.gov.il
- CVE-Watchlists
- Unerledigt
Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Chcnav ≫ P5e Gnss Firmware Version4.1
Chcnav ≫ P5e Gnss Firmware Version4.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.337 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| cna@cyber.gov.il | 5.7 | 1.5 | 3.7 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-548 Exposure of Information Through Directory Listing
A directory listing is inappropriately exposed, yielding potentially sensitive information to attackers.