Lucene search

K
cvelistINCDCVELIST:CVE-2022-30623
HistoryJul 18, 2022 - 12:59 p.m.

CVE-2022-30623 Chcnav - P5E GNSS Authentication bypass

2022-07-1812:59:03
CWE-288
INCD
www.cve.org
5
cve-2022-30623
chcnav
authentication bypass
gnss

CVSS3

5.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

57.3%

The server checks the user’s cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.

CNA Affected

[
  {
    "product": "Chcnav - P5E GNSS",
    "vendor": "Chcnav",
    "versions": [
      {
        "lessThan": "4.1*",
        "status": "affected",
        "version": "4.2",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

57.3%

Related for CVELIST:CVE-2022-30623