8.8
CVE-2022-45183
- EPSS 0.48%
- Veröffentlicht 14.11.2022 08:15:09
- Zuletzt bearbeitet 21.11.2024 07:28:55
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ironmansoftware ≫ Powershell Universal Version >= 2.0.0 < 2.12.6
Ironmansoftware ≫ Powershell Universal Version >= 3.0.0 < 3.4.7
Ironmansoftware ≫ Powershell Universal Version >= 3.5.0 < 3.5.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.644 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.