7.5
CVE-2022-46901
- EPSS 0.1%
- Veröffentlicht 25.07.2023 20:15:13
- Zuletzt bearbeitet 21.11.2024 07:31:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and backing up, loading, and clearing of the database.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vocera ≫ Report Server Version >= 5.0.0 <= 5.8.0.135
Vocera ≫ Voice Server Version >= 5.0.0 <= 5.8.0.135
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.273 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.