8.1
CVE-2022-33202
- EPSS 0.1%
- Veröffentlicht 27.06.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 07:07:42
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by using alternative paths or channels for Sensor.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Softcreate ≫ L2blocker SwEditioncloud Version < 4.8.6
Softcreate ≫ L2blocker SwEditionon-premise Version < 4.8.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.284 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 4.8 | 6.5 | 4.9 |
AV:A/AC:L/Au:N/C:P/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.