Lucene search

K
cve[email protected]CVE-2022-35262
HistoryOct 25, 2022 - 5:15 p.m.

CVE-2022-35262

2022-10-2517:15:53
CWE-125
web.nvd.nist.gov
29
4
cve-2022-35262
denial of service
robustel r1510
web_server
hashfirst
import_xml_file
api
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

30.9%

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of service is in the /action/import_xml_file/ API.

Affected configurations

Vulners
NVD
Node
robustelr1510Range3.1.16
OR
robustelr1510Range3.3.0
VendorProductVersionCPE
robustelr1510*cpe:2.3:h:robustel:r1510:*:*:*:*:*:*:*:*
robustelr1510*cpe:2.3:h:robustel:r1510:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Robustel",
    "product": "R1510",
    "versions": [
      {
        "version": "3.1.16",
        "status": "affected"
      },
      {
        "version": "3.3.0",
        "status": "affected"
      }
    ]
  }
]

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

30.9%

Related for CVE-2022-35262