5.7

CVE-2022-30625

Chcnav - P5E GNSS Directory listing

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ChcnavP5e Gnss Firmware Version4.1
   ChcnavP5e Gnss Version-
ChcnavP5e Gnss Firmware Version4.2
   ChcnavP5e Gnss Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.243
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cna@cyber.gov.il 5.7 1.5 3.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-548 Exposure of Information Through Directory Listing

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

https://www.gov.il/en/Departments/faq/cve_advisories
Third Party Advisory