8.7
CVE-2022-38123
- EPSS 0.52%
- Veröffentlicht 06.12.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:15:50
- Quelle VulnerabilityReporting@secomea
- CVE-Watchlists
- Unerledigt
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Secomea ≫ Gatemanager Version < 10.0.622395010
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.661 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| VulnerabilityReporting@secomea.com | 8.7 | 2.3 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.