Lucene search

K
cveINCDCVE-2022-30623
HistoryJul 18, 2022 - 1:15 p.m.

CVE-2022-30623

2022-07-1813:15:10
CWE-287
CWE-288
INCD
web.nvd.nist.gov
57
6
cve-2022-30623
server security
identification bypass
cookie vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

57.3%

The server checks the user’s cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.

Affected configurations

Nvd
Node
chcnavp5e_gnss_firmwareMatch4.1
OR
chcnavp5e_gnss_firmwareMatch4.2
AND
chcnavp5e_gnssMatch-
VendorProductVersionCPE
chcnavp5e_gnss_firmware4.1cpe:2.3:o:chcnav:p5e_gnss_firmware:4.1:*:*:*:*:*:*:*
chcnavp5e_gnss_firmware4.2cpe:2.3:o:chcnav:p5e_gnss_firmware:4.2:*:*:*:*:*:*:*
chcnavp5e_gnss-cpe:2.3:h:chcnav:p5e_gnss:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Chcnav - P5E GNSS",
    "vendor": "Chcnav",
    "versions": [
      {
        "lessThan": "4.1*",
        "status": "affected",
        "version": "4.2",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

57.3%

Related for CVE-2022-30623