Lucene search

K
cveJpcertCVE-2022-41642
HistoryDec 05, 2022 - 4:15 a.m.

CVE-2022-41642

2022-12-0504:15:09
CWE-78
jpcert
web.nvd.nist.gov
28
cve-2022-41642
os command injection
nadesiko3
pc version
vulnerability
security
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.005

Percentile

77.8%

OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.

Affected configurations

Nvd
Vulners
Node
kujirahandnadesiko3Range3.3.68
VendorProductVersionCPE
kujirahandnadesiko3*cpe:2.3:a:kujirahand:nadesiko3:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "kujirahand",
    "product": "Nadesiko3 (PC Version)",
    "versions": [
      {
        "version": "v3.3.61 and earlier",
        "status": "affected"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.005

Percentile

77.8%