Lucene search

K
cvelistIcscertCVELIST:CVE-2022-2332
HistorySep 16, 2022 - 8:18 p.m.

CVE-2022-2332 Honeywell SoftMaster Incorrect Permission Assignment for Critical Resource

2022-09-1620:18:45
CWE-732
icscert
www.cve.org
3
cve-2022-2332
honeywell softmaster
incorrect permission assignment
critical resource

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.8

Confidence

High

EPSS

0

Percentile

10.4%

A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment.

CNA Affected

[
  {
    "product": "SoftMaster",
    "vendor": "Honeywell",
    "versions": [
      {
        "status": "affected",
        "version": "4.51"
      }
    ]
  }
]

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.8

Confidence

High

EPSS

0

Percentile

10.4%

Related for CVELIST:CVE-2022-2332