Lucene search

K
cveJpcertCVE-2022-46282
HistoryDec 21, 2022 - 9:15 a.m.

CVE-2022-46282

2022-12-2109:15:08
CWE-416
jpcert
web.nvd.nist.gov
36
cve-2022-46282
use after free vulnerability
cx-drive
nvd
security
arbitrary code
local attacker

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

26.3%

Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially crafted file,

Affected configurations

Nvd
Vulners
Node
omroncx-driveRange3.00
VendorProductVersionCPE
omroncx-drive*cpe:2.3:a:omron:cx-drive:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "OMRON Corporation",
    "product": "CX-Drive",
    "versions": [
      {
        "version": "V3.00 and earlier",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

26.3%

Related for CVE-2022-46282