Lucene search

K
certCERTVU:473698
HistoryMay 09, 2022 - 12:00 a.m.

uClibc, uClibc-ng libraries have monotonically increasing DNS transaction ID

2022-05-0900:00:00
www.kb.cert.org
32

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

0.001 Low

EPSS

Percentile

46.5%

Overview

The uClibc and uClibc-ng libraries, prior to uClibc-ng 1.0.41, are vulnerable to DNS cache poisoning due to the use of predicatble DNS transaction IDs when making DNS requests. This vulnerability can allow an attacker to perform DNS cache poisoning attacks against a vulnerable environment.

Description

The uClibc and the Uclibc-ng software are lightweight C standard libraries intended for use in embedded systems and mobile devices. The uClibc library has not been updated since May of 2012. The newer uClibc-ng is the currently maintained fork of uClibc, as announced on the OpenWRT mailing list in July 2014.

Researchers at the Nozomi Networks Security Research Team discovered that all existing versions of uClibc and uClibc-ng libraries are vulnerable to DNS cache poisoning. These libraries do not employ any randomization in the DNS Transaction ID (DNS TXID) field when creating a new DNS request. This can allow an attacker to send maliciously crafted DNS packets to corrupt the DNS cache with invalid entries and redirect users to arbitrary sites. As uClibc and uClibc-ng are used in devices such as home routers and firewalls, an attacker can perform attacks against multiple users in a shared network environment that relies on DNS responses from the vulnerable device.

The DNS cache poisoning scenarios and defenses are discussed in IETF RFC5452.

Impact

The lack of DNS response validation can allow an attacker to use unsolicited DNS responses to poison the DNS cache and redirect users to malicious sites.

Solution

Apply a patch

If your vendor has developed a patched version of uClibc or uClibc-ng to address this issue, apply the updates provided by your vendor. uClibc-ng was updated to 1.0.41 on 05/20/2022.

Product Developers

If you have a forked or customized version of uClibc or uClibc-ng, develop or adopt a patch to ensure the dns_lookup function provides adequate randomization of DNS TXID’s while making DNS requests. Review and consider applying the patch has been made available in patchwork repository of uClibc-ng with VU#638879 tag.

Follow security best practices

Consider the following security best-practices to protect DNS infrastructure:

  • Prevent direct exposure of IoT devices and lightweight devices over the Internet to minimize attacks against a caching DNS server.
  • Provide secure DNS recursion service with features such as DNSSEC validation and the interim 0x20-bit encoding as part of enterprise DNS recursion services where applicable.
  • Implement a Secure By Default configuration suitable for your operating environment (e.g., disable caching on embedded IoT devices when an upstream caching resolver is available).

Acknowledgements

Thanks to the Nozomi Networks Security Research Team for this report

This document was written by Vijay Sarvepalli and Timur Snoke.

Vendor Information

473698

Filter by status: All Affected Not Affected Unknown

Filter by content: __ Additional information available

__ Sort by: Status Alphabetical

Expand all

Digi International __ Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: March 22, 2022

CVE-2022-30295 Affected

Vendor Statement

We have two active devices using uClibc AND susceptible to this based on version: ConnectCore 9P 9215

ConnectME 9210 We will patch once it is available.

Abbott Labs Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: March 02, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Actiontec __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: March 11, 2022

CVE-2022-30295 Not Affected

Vendor Statement

Our products use Glibc instead of UClibc.

Advantech Czech Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Aruba Networks Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: March 21, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Aveva Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: March 16, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

AVM GmbH __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: February 10, 2022

CVE-2022-30295 Not Affected

Vendor Statement

All DNS requests made by userland apps go through a DNS caching resolver before beeing sent to the Internet. The DNS caching resolver implements a transaction-ID/source port randomization that is indepent from what was generated by a userland program (whatever c-library it used).

B. Braun Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: February 01, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

BOSCH Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: May 03, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Brocade Communication Systems __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: April 06, 2022

CVE-2022-30295 Not Affected

Vendor Statement

No Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.

Check Point Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 25, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Crestron Electronics Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 26, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Dell SecureWorks Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

eCosCentric __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 26, 2022

CVE-2022-30295 Not Affected

Vendor Statement

This code is not in our RTOS

F5 Networks __ Not Affected

Notified: 2022-01-24 Updated: 2023-04-04

Statement Date: April 04, 2023

CVE-2022-30295 Not Affected

Vendor Statement

F5 does not use uClibc or uClibc-ng in any products.

Fanuc America __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-10

Statement Date: May 10, 2022

CVE-2022-30295 Not Affected

Vendor Statement

I confirmed the use of uClibc to all robot software group. There is no use of it in FANUC Robot Controller

Fuji_Electric_Hakko_Electric __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: May 09, 2022

CVE-2022-30295 Not Affected

Vendor Statement

To the knowledge of our development team, we are not at risk or do not use the afore mentioned components that would create the vulnerability.

Google Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: February 07, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

HardenedBSD __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: February 01, 2022

CVE-2022-30295 Not Affected

Vendor Statement

HardenedBSD supports neither uClibc nor uClibc-ng.

Iconics Inc. Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: May 03, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Illumos __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Not Affected

Vendor Statement

uClibc is not in base illumos. Distributions, however, may use them, but a quick survey suggests not in mandatory distribution software.

Internet Initiative Japan Inc. Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 25, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Joyent __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Not Affected

Vendor Statement

SmartOS (an illumos distribution) is not affected by this issue, nor is our Triton cloud management system.

Juniper Networks __ Not Affected

Notified: 2022-01-24 Updated: 2023-02-22

Statement Date: February 22, 2023

CVE-2022-30295 Not Affected

Vendor Statement

Based on our investigation we confirm that there are no platforms/products which are affected from these vulnerabilities.

Security Incident Response Team Juniper Networks

lwIP Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

McAfee Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Miredo Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Moxa __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-23

Statement Date: May 23, 2022

CVE-2022-30295 Not Affected

Vendor Statement

Dear all,

Moxa is investigating the vulnerability and has determined that none of our products are currently affected. Thank you for the information and notification.

Sincerely, Moxa PSIRT

Muonics Inc. __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 25, 2022

CVE-2022-30295 Not Affected

Vendor Statement

Muonics does not use uClibc or uClibc-ng libraries in any of its products and thus this vulnerability is not applicable.

OpenWRT __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: March 21, 2022

CVE-2022-30295 Not Affected

Vendor Statement

OpenWrt 19.07 is using uClibc-ng only on Synopsys ARC CPUs, all other targets are using musl libc by default. musl libc and glibc are not affected by this problem. OpenWrt 21.02 and later are not using uClibc-ng or uClibc at all. These versions are not affected by the problem. Synopsys ARC CPUs switched to glibc in OpenWrt 21.02.

OpenWrt 19.07 is end of life since March 2022 and we will not fix this problem in OpenWrt 19.07 or any other version.

Paessler Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: April 04, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Peplink __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: May 03, 2022

CVE-2022-30295 Not Affected

Vendor Statement

No use of uClibc and uClibc-ng in our products.

pfSense Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: April 01, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Real-Time Innovations (RTI) __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: May 09, 2022

CVE-2022-30295 Not Affected

Vendor Statement

RTI products don’t use uClibc or uClibc-ng libraries.

Rockwell Automation __ Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Not Affected

Vendor Statement

I have checked our SBOM library and we are not vulnerable to this.

Sierra Wireless Not Affected

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: February 10, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

SUSE Linux __ Not Affected

Notified: 2022-05-26 Updated: 2022-07-06

Statement Date: June 07, 2022

CVE-2022-30295 Not Affected

Vendor Statement

SUSE is not shipping uClibc in any of its current products at this time.

Synology Not Affected

Notified: 2022-05-26 Updated: 2022-05-27

Statement Date: May 27, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Treck Not Affected

Notified: 2022-05-26 Updated: 2022-05-27

Statement Date: May 27, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Triangle Microworks Not Affected

Notified: 2022-05-26 Updated: 2022-06-06

Statement Date: June 03, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Ubuntu __ Not Affected

Notified: 2022-05-26 Updated: 2022-08-29

Statement Date: August 23, 2022

CVE-2022-30295 Not Affected

Vendor Statement

uCLibc was removed from the Ubuntu archives in 2011, and uClibc-ng has never been included in Ubuntu.

Wind River Not Affected

Notified: 2022-05-26 Updated: 2022-05-27

Statement Date: May 27, 2022

CVE-2022-30295 Not Affected

Vendor Statement

We have not received a statement from the vendor.

MikroTik __ Unknown

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Unknown

Vendor Statement

MikroTik RouterOS v7.x.x does not use uClibc

A10 Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ABB Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ACCESS Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Actelis Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ADATA Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ADTRAN Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Advantech B-B Technology Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Advantech Taiwan Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Aerohive Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

AhnLab Inc Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

AirWatch Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Akamai Technologies Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: May 02, 2022

CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Alcatel-Lucent Enterprise Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Allied Telesis Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Alpine Linux Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Alstom Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Altran Intelligent Systems Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Amazon Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

AMTELCO Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Analog Devices Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 24, 2022

CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Android Open Source Project Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ANTlabs Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Apple Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Arcadyan Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Arch Linux Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Arista Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ARRIS Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ASUSTeK Computer Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Atheros Communications Inc Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

AT&T Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Automated Solutions Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Avaya Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Barracuda Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Baxter US Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Belden Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Belkin Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Bell Canada Enterprises Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

BlackBerry Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Blackberry QNX Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

BlueCat Networks Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Blue Coat Systems Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Blunk Microsystems Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

BoringSSL Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Broadcom Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Buffalo Technology Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Cambium Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Canon Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Carel Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

CareStream Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

CA Technologies Unknown

Notified: 2022-01-24 Updated: 2022-05-09

Statement Date: January 25, 2022

CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Caterpillar Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Ceragon Networks Inc Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Cirpack Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Cisco Unknown

Notified: 2022-01-24 Updated: 2022-07-12

Statement Date: July 11, 2022

CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

CMX Systems Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Comcast Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Commscope Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Contiki OS Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Cradlepoint Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Cricket Wireless Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Cypress Semiconductor Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

CZ.NIC Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Daktronics Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

dd-wrt Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Debian GNU/Linux Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Dell Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Dell EMC Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

DesktopBSD Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Deutsche Telekom Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Devicescape Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

D-Link Systems Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

dnsmasq Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

DragonFly BSD Project Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Eaton Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

eero Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

EfficientIP Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ENEA Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Ericsson Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Espressif Systems Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

European Registry for Internet Domains Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Express Logic Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Extreme Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Fastly Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Fedora Project Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Fiat Chrysler Automobiles Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

FNet Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Force10 Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Fortinet Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

FreeBSD Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

FreeRTOS Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

F-Secure Corporation Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

General Electric Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Gentoo Linux Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

GFI Software Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

GNU adns Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

GNU glibc Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Grandstream Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Green Hills Software Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

HCC Embedded Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Hewlett Packard Enterprise Unknown

Notified: 2022-01-24 Updated: 2022-07-06

Statement Date: June 24, 2022

CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Hitachi Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Hitachi Energy Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Honeywell Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

HP Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

HTC Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Huawei Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

IBM Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

IBM Corporation (zseries) Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

IBM Numa-Q Division (Formerly Sequent) Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ICASI Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Infoblox Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

InfoExpress Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Inmarsat Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Intel Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Internet Systems Consortium Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Internet Systems Consortium - DHCP Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Invensys Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

IP Infusion Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

JH Software Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Johnson Controls Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

JPCERT/CC Vulnerability Handling Team Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

KMC Controls Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

kubernetes Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

LANCOM Systems GmbH Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Lancope Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Lantronix Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Lenovo Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

LG Electronics Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

LibreSSL Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Linksys Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

LITE-ON Technology Corporation Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

LiteSpeed Technologies Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Lynx Software Technologies Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

m0n0wall Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Marconi Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Marvell Semiconductor Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

MediaTek Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Medtronic Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Meinberg Funkuhren GmbH & Co. KG Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Men & Mice Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Metaswitch Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Microchip Technology Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Micro Focus Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Microsoft Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Mitel Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Mitsubishi Electric Corporation Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Monroe Electronics Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Motorola Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

National Cyber Security Center Netherlands Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

National Cyber Security Centre Finland Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

NCSC-FI Vulnerability Coordinator Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

NEC Corporation Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

NetBSD Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

NetBurner Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

NetComm Wireless Limited Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

NETGEAR Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

NETSCOUT Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

netsnmp Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

netsnmpj Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Nexenta Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

NIKSUN Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Nixu Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

NLnet Labs Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Nokia Unknown

Notified: 2022-01-24 Updated: 2022-07-12

Statement Date: July 12, 2022

CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

OleumTech Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

OpenBSD Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

OpenConnect Ltd Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

OpenDNS Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

OpenIndiana Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

OpenSSL Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Openwall GNU/*/Linux Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Oracle Corporation Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Oryx Embedded Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Palo Alto Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Panasonic Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Philips Electronics Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Philips Healthcare Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Phoenix Contact Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

PHPIDS Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

PowerDNS Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Proxim Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Pulse Secure Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

QLogic Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

QNAP Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Quadros Systems Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Quagga Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Qualcomm Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Quantenna Communications Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

RealFlex Technologies Ltd Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Red Hat Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Red Lion Controls Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Riverbed Technologies Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Roku Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Ruckus Wireless Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Ruijie Networks Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Sabre Airline Solutions Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Samsung Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Samsung Mobile Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Samsung Semiconductor Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Schneider Electric Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Secure64 Software Corporation Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

SEIKO EPSON Corp. / Epson America Inc. Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Siemens Unknown

Notified: 2022-01-24 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Slackware Linux Inc. Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

SMC Networks Inc. Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

SmoothWall Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Snort Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

SonicWall Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Sonos Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Sony Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Sophos Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Sourcefire Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Symantec Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

systemd Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

TCPWave Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

TDS Telecom Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Technicolor Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Tenable Network Security Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Tesla Motors Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Thales Group Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

The OpenBSD project Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

TippingPoint Technologies Inc. Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Tizen Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

TP-LINK Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Trane Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Tropos Networks Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

TrueOS Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Turbolinux Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Ubiquiti Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

uClibc-ng Unknown

Notified: 2021-11-29 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Unisys Corporation Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Univention Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Untangle Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

VMware Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Vultures List Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Wago Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

WECON Technology Co Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Wibu-Systems Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

WizNET Technology Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

wolfSSL Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Xiaomi Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

XigmaNAS Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Xilinx Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Xylem Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Zebra Technologies Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Zephyr Project Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Zoll Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Zonare/Mindray Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

ZTE Corporation Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

Zyxel Unknown

Notified: 2022-05-26 Updated: 2022-05-09 CVE-2022-30295 Unknown

Vendor Statement

We have not received a statement from the vendor.

View all 293 vendors __View less vendors __

References

Other Information

CVE IDs: CVE-2022-30295
API URL: VINCE JSON
Date Public: 2022-05-02 Date First Published:

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

0.001 Low

EPSS

Percentile

46.5%