Lucene search

K
cveVulDBCVE-2022-2664
HistoryAug 05, 2022 - 11:15 a.m.

CVE-2022-2664

2022-08-0511:15:07
CWE-287
VulDB
web.nvd.nist.gov
2074
4
cve-2022-2664
private cloud
management platform
vulnerability
nvd
remote authentication

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

58.3%

A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It is possible to launch the attack remotely. VDB-205614 is the identifier assigned to this vulnerability.

Affected configurations

Nvd
Node
private_cloud_management_platform_projectprivate_cloud_management_platformMatch-
VendorProductVersionCPE
private_cloud_management_platform_projectprivate_cloud_management_platform-cpe:2.3:a:private_cloud_management_platform_project:private_cloud_management_platform:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Private Cloud Management Platform",
    "vendor": "unspecified",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

58.3%

Related for CVE-2022-2664