7.7

CVE-2022-32958

TEAMPLUS TECHNOLOGY INC. Teamplus Pro - Allocation of Resources Without Limits or Throttling

A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size limit, to terminate other recipients’ Teamplus Pro chat process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TeamplusTeam+ Pro SwEditionprivate_cloud SwPlatformandroid Version <= 3.011.6.0.1
TeamplusTeam+ Pro SwEditionprivate_cloud SwPlatformiphone_os Version <= 3.011.6.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.93% 0.573
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Cert TW 7.7 3.1 4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://www.twcert.org.tw/tw/cp-132-6289-a5524-1.html
Third Party Advisory