Lucene search

K
cveINCDCVE-2022-30625
HistoryJul 18, 2022 - 1:15 p.m.

CVE-2022-30625

2022-07-1813:15:10
CWE-548
CWE-200
INCD
web.nvd.nist.gov
39
6
cve-2022-30625
directory listing
web server
security
nvd

CVSS3

5.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

31.3%

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.

Affected configurations

Nvd
Node
chcnavp5e_gnss_firmwareMatch4.1
OR
chcnavp5e_gnss_firmwareMatch4.2
AND
chcnavp5e_gnssMatch-
VendorProductVersionCPE
chcnavp5e_gnss_firmware4.1cpe:2.3:o:chcnav:p5e_gnss_firmware:4.1:*:*:*:*:*:*:*
chcnavp5e_gnss_firmware4.2cpe:2.3:o:chcnav:p5e_gnss_firmware:4.2:*:*:*:*:*:*:*
chcnavp5e_gnss-cpe:2.3:h:chcnav:p5e_gnss:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Chcnav - P5E GNSS",
    "vendor": "Chcnav",
    "versions": [
      {
        "lessThan": "4.1*",
        "status": "affected",
        "version": "4.2",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

5.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

31.3%

Related for CVE-2022-30625