Lucene search

K
cveKrcertCVE-2022-41157
HistoryNov 25, 2022 - 7:15 p.m.

CVE-2022-41157

2022-11-2519:15:11
CWE-798
krcert
web.nvd.nist.gov
33
9
vulnerability
kyungrinara
erp
fixed password
system authority
information leakage
sensitive information
malicious commands

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

58.3%

A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands.

Affected configurations

Nvd
Node
microsoftwindowsMatch-
AND
webcashserp_server_2.0Range<20.2.161
VendorProductVersionCPE
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
webcashserp_server_2.0*cpe:2.3:a:webcash:serp_server_2.0:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Webcash Co.,Ltd",
    "product": "sERP Server 2.0",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "20.2.161",
        "status": "affected",
        "versionType": "custom"
      }
    ],
    "platforms": [
      "Windows"
    ]
  }
]

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

58.3%

Related for CVE-2022-41157