Lucene search

K
cveBitdefenderCVE-2022-2472
HistorySep 15, 2022 - 2:15 p.m.

CVE-2022-2472

2022-09-1514:15:09
CWE-665
Bitdefender
web.nvd.nist.gov
33
4
cve-2022-2472
ezviz
vulnerability
security
initialization
local server
memory space
admin password

CVSS3

7.6

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

5.1

Confidence

High

EPSS

0

Percentile

5.1%

Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to read the contents of the memory space containing the encrypted admin password. This issue affects: EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428.

Affected configurations

Nvd
Node
ezvizcs-c6n-a0-1c2wfr_firmwareMatch5.3.0build220428
AND
ezvizcs-c6n-a0-1c2wfrMatch-
VendorProductVersionCPE
ezvizcs-c6n-a0-1c2wfr_firmware5.3.0cpe:2.3:o:ezviz:cs-c6n-a0-1c2wfr_firmware:5.3.0:build220428:*:*:*:*:*:*
ezvizcs-c6n-a0-1c2wfr-cpe:2.3:h:ezviz:cs-c6n-a0-1c2wfr:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "CS-C6N-A0-1C2WFR",
    "vendor": "EZVIZ",
    "versions": [
      {
        "lessThan": "5.3.0 build 220428",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.6

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

5.1

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2022-2472