5.3
CVE-2022-44593
- EPSS 0.09%
- Veröffentlicht 21.06.2024 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:28:11
- Quelle audit@patchstack.com
- CVE-Watchlists
- Unerledigt
Solid Security <= 9.3.1 - IP Address Spoofing to Denial of Service
Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.
Mögliche Gegenmaßnahme
Solid Security – Password, Two Factor Authentication, and Brute Force Protection: Update to version 9.3.2, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Solid Security – Password, Two Factor Authentication, and Brute Force Protection
Version
*-9.3.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Solidwp ≫ Solid Security SwPlatformwordpress Version < 9.3.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.256 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
| audit@patchstack.com | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-348 Use of Less Trusted Source
The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.