5.3

CVE-2022-44593

Solid Security <= 9.3.1 - IP Address Spoofing to Denial of Service

Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.
Mögliche Gegenmaßnahme
Solid Security – Password, Two Factor Authentication, and Brute Force Protection: Update to version 9.3.2, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Solid Security – Password, Two Factor Authentication, and Brute Force Protection
Version *-9.3.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SolidwpSolid Security SwPlatformwordpress Version < 9.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.256
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
audit@patchstack.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CWE-348 Use of Less Trusted Source

The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.