Lucene search

K
cve[email protected]CVE-2022-38355
HistoryDec 13, 2022 - 10:15 p.m.

CVE-2022-38355

2022-12-1322:15:10
CWE-284
web.nvd.nist.gov
33
cve-2022-38355
daikin
svmpc1
svmpc2
vulnerability
lan
information disclosure

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.2%

Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to

attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication.

Affected configurations

NVD
Node
daikinlatamsvmpc1Range2.1.22
OR
daikinlatamsvmpc2Range1.2.3

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SVMPC1 ",
    "vendor": "Daikin",
    "versions": [
      {
        "lessThanOrEqual": "2.1.22",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "SVMPC2",
    "vendor": "Daikin",
    "versions": [
      {
        "lessThanOrEqual": "1.2.3",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.2%

Related for CVE-2022-38355