Lucene search

K
cvelistIcscertCVELIST:CVE-2022-1523
HistoryAug 30, 2022 - 12:00 a.m.

CVE-2022-1523 Fuji Electric D300win Write-what-where condition

2022-08-3000:00:00
CWE-123
icscert
www.cve.org
cve-2022-1523
fuji electric
d300win
write-what-where
vulnerability
program memory

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.4%

Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to a write-what-where condition, which could allow an attacker to overwrite program memory to manipulate the flow of information.

CNA Affected

[
  {
    "vendor": "Fuji Electric",
    "product": "D300win",
    "versions": [
      {
        "version": "3.7.1.16",
        "status": "affected",
        "lessThan": "3.7.1.17",
        "versionType": "custom"
      }
    ]
  }
]

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.4%

Related for CVELIST:CVE-2022-1523