Lucene search

K
cvelistTwcertCVELIST:CVE-2022-26669
HistoryJun 20, 2022 - 5:30 a.m.

CVE-2022-26669 ASUS Control Center - SQL Injection

2022-06-2005:30:31
CWE-89
twcert
www.cve.org
5
asus control center
sql injection
cve-2022-26669
remote attacker
database access

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

34.5%

ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data.

CNA Affected

[
  {
    "product": "Control Center",
    "vendor": "ASUS",
    "versions": [
      {
        "status": "affected",
        "version": "1.4.2.5"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

34.5%

Related for CVELIST:CVE-2022-26669