Lucene search

K
cvelistIcscertCVELIST:CVE-2022-1067
HistoryApr 11, 2022 - 7:38 p.m.

CVE-2022-1067 ICSMA-22-095-01 LifePoint Informatics Patient Portal

2022-04-1119:38:15
CWE-288
icscert
www.cve.org
2
cve-2022-1067
icsma-22-095-01
pdf generation
lab report
authentication
rate limiting

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

28.4%

Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting.

CNA Affected

[
  {
    "product": "Patient Portal",
    "vendor": "LifePoint Informatics",
    "versions": [
      {
        "lessThan": "LPI 3.5.12.P30",
        "status": "affected",
        "version": "All",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

28.4%

Related for CVELIST:CVE-2022-1067