5
CVE-2022-34428
- EPSS 0.3%
- Veröffentlicht 30.09.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:09:32
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell Hybrid Client prior to version 1.8 contains a Regular Expression Denial of Service Vulnerability in the UI. An adversary with WMS group admin access could potentially exploit this vulnerability, leading to temporary denial-of-service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Hybrid Client Version1.5
Dell ≫ Hybrid Client Version1.6
Dell ≫ Hybrid Client Version1.6.1
Dell ≫ Hybrid Client Version1.6.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.525 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.7 | 1.2 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
|
| security_alert@emc.com | 5 | 3.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
|
CWE-1333 Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.