Lucene search

K
cve[email protected]CVE-2022-1660
HistoryJun 02, 2022 - 2:15 p.m.

CVE-2022-1660

2022-06-0214:15:32
CWE-502
web.nvd.nist.gov
63
2
cve-2022-1660
vulnerability
untrusted data
deserialization
remote code execution
authorization
authentication
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.1%

The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.

Affected configurations

NVD
Node
keysightn6854aMatch-
AND
keysightn6854a_firmwareRange<2.4.0
Node
keysightn6841a_rfMatch-
AND
keysightn6841a_rf_firmwareRange<2.4.0

CNA Affected

[
  {
    "product": "N6854A Geolocation server and N6841A RF Sensor software",
    "vendor": "Keysight",
    "versions": [
      {
        "lessThan": "2.3.0",
        "status": "affected",
        "version": "all",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.1%