8.1
CVE-2022-36174
- EPSS 0.19%
- Veröffentlicht 12.09.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:12:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freshworks ≫ Freshservice Agent SwPlatformwindows Version < 2.11.0
Freshworks ≫ Freshservice Agent SwPlatformlinux Version < 3.3.0
Freshworks ≫ Freshservice Agent SwPlatformmacos Version < 4.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.413 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-354 Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.