Lucene search

K
cve[email protected]CVE-2022-32292
HistoryAug 03, 2022 - 2:15 p.m.

CVE-2022-32292

2022-08-0314:15:08
CWE-787
web.nvd.nist.gov
54
7
cve-2022-32292
connman
remote attack
http request
heap-based
buffer overflow
code execution

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.6 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.0%

In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.

Affected configurations

NVD
Node
intelconnmanRange1.41
Node
debiandebian_linuxMatch11.0
CPENameOperatorVersion
intel:connmanintel connmanle1.41

Social References

More

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.6 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.0%