Lucene search

K
cveNECCVE-2022-34825
HistoryNov 08, 2022 - 10:15 p.m.

CVE-2022-34825

2022-11-0822:15:14
CWE-427
NEC
web.nvd.nist.gov
39
4
cve-2022-34825
information security
uncontrolled search path
windows
remote code execution

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

73.8%

Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system and to potentially execute arbitrary code.

Affected configurations

Nvd
Node
necexpresscluster_xRange5.0windows
OR
necexpresscluster_x_singleserversafeRange5.0windows
VendorProductVersionCPE
necexpresscluster_x*cpe:2.3:a:nec:expresscluster_x:*:*:*:*:*:windows:*:*
necexpresscluster_x_singleserversafe*cpe:2.3:a:nec:expresscluster_x_singleserversafe:*:*:*:*:*:windows:*:*

CNA Affected

[
  {
    "vendor": "NEC Corporation",
    "product": "CLUSTERPRO X",
    "versions": [
      {
        "version": "CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

73.8%

Related for CVE-2022-34825