Lucene search

K
cvelistTalosCVELIST:CVE-2022-28664
HistoryAug 05, 2022 - 9:20 p.m.

CVE-2022-28664

2022-08-0521:20:13
CWE-787
talos
www.cve.org
5
memory corruption
freshtomato
httpd
vulnerability
network request
url-decoding
cve

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

9.8

Confidence

High

EPSS

0.008

Percentile

82.3%

A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The freshtomato-mips has a vulnerable URL-decoding feature that can lead to memory corruption.

CNA Affected

[
  {
    "vendor": "FreshTomato",
    "product": "FreshTomato",
    "versions": [
      {
        "version": "2022.1",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

9.8

Confidence

High

EPSS

0.008

Percentile

82.3%

Related for CVELIST:CVE-2022-28664