6.8
CVE-2022-32962
- EPSS 0.07%
- Veröffentlicht 20.07.2022 02:15:07
- Zuletzt bearbeitet 21.11.2024 07:07:19
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hinet ≫ Hicos Natural Person Credential Component Client Version3.0.3.30306 SwPlatformlinux
Hinet ≫ Hicos Natural Person Credential Component Client Version3.0.3.30404 SwPlatformmacos
Hinet ≫ Hicos Natural Person Credential Component Client Version3.1.0.00002 SwPlatformwindows
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.221 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| twcert@cert.org.tw | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-415 Double Free
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.