Lucene search

K
cveSchneiderCVE-2022-32512
HistoryJan 30, 2023 - 11:15 p.m.

CVE-2022-32512

2023-01-3023:15:09
CWE-119
schneider
web.nvd.nist.gov
27
cve-2022-32512
canbrass
memory buffer
remote code execution
vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

46.2%

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code execution when a command which exploits this vulnerability is utilized. Affected Products: CanBRASS (Versions prior to V7.5.1)

Affected configurations

Nvd
Node
schneider-electriccanbrassRange<7.5.1
VendorProductVersionCPE
schneider-electriccanbrass*cpe:2.3:a:schneider-electric:canbrass:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Schneider Electric",
    "product": "CanBRASS",
    "versions": [
      {
        "version": "All",
        "status": "affected",
        "lessThan": "V7.5.1",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

46.2%

Related for CVE-2022-32512