Lucene search

K
cveSophosCVE-2022-4901
HistoryMar 01, 2023 - 7:15 p.m.

CVE-2022-4901

2023-03-0119:15:25
CWE-79
Sophos
web.nvd.nist.gov
30
cve-2022-4901
sophos connect
stored xss
vulnerability
nvd
security
vpn configuration

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

32.1%

Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.

Affected configurations

Nvd
Node
sophosconnectRange<2.2.90
VendorProductVersionCPE
sophosconnect*cpe:2.3:a:sophos:connect:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Sophos",
    "product": "Sophos Connect Client",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "2.2.90",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

32.1%

Related for CVE-2022-4901