Lucene search

K
cveMitreCVE-2022-25008
HistoryMar 30, 2022 - 11:15 p.m.

CVE-2022-25008

2022-03-3023:15:08
CWE-306
mitre
web.nvd.nist.gov
63
cve
2022
totolink
ex300_v2
ex1200t
authentication
mechanism
security
vulnerability
nvd

CVSS2

5.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

52.1%

totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.

Affected configurations

Nvd
Node
totolinkex300_v2_firmwareMatch4.0.3c.140_b20210429
AND
totolinkex300_v2Match-
Node
totolinkex1200t_firmwareMatch4.1.2cu.5230_b20210706
AND
totolinkex1200tMatch-
VendorProductVersionCPE
totolinkex300_v2_firmware4.0.3c.140_b20210429cpe:2.3:o:totolink:ex300_v2_firmware:4.0.3c.140_b20210429:*:*:*:*:*:*:*
totolinkex300_v2-cpe:2.3:h:totolink:ex300_v2:-:*:*:*:*:*:*:*
totolinkex1200t_firmware4.1.2cu.5230_b20210706cpe:2.3:o:totolink:ex1200t_firmware:4.1.2cu.5230_b20210706:*:*:*:*:*:*:*
totolinkex1200t-cpe:2.3:h:totolink:ex1200t:-:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

52.1%

Related for CVE-2022-25008