7.5

CVE-2022-30627

This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, update_b5_v2.0.9_b20200706. This vulnerability makes it possible to extract from the FW the existing user passwords on their operating systems and passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ChcnavP5e Gnss Firmware Version4.1
   ChcnavP5e Gnss Version-
ChcnavP5e Gnss Firmware Version4.2
   ChcnavP5e Gnss Version-
ChcnavP5e Gnss Firmware Versionupdate_b5_v2.0.9_b20200706
   ChcnavP5e Gnss Version-
ChcnavP5e Gnss Firmware Versionupdate_i50_v1.0.55_b20200509
   ChcnavP5e Gnss Version-
ChcnavP5e Gnss Firmware Versionupdate_i90_cv2.021_b20210104
   ChcnavP5e Gnss Version-
ChcnavP5e Gnss Firmware Versionupdate_x6_v2.1.2_b202001127
   ChcnavP5e Gnss Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.325
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cna@cyber.gov.il 5.7 1.5 3.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.