Lucene search

K
cvelistINCDCVELIST:CVE-2022-30625
HistoryJul 18, 2022 - 12:58 p.m.

CVE-2022-30625 Chcnav - P5E GNSS Directory listing

2022-07-1812:58:39
CWE-548
INCD
www.cve.org
3
web server function
directory listing
index file
resource access

CVSS3

5.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

31.3%

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.

CNA Affected

[
  {
    "product": "Chcnav - P5E GNSS",
    "vendor": "Chcnav",
    "versions": [
      {
        "lessThan": "4.1*",
        "status": "affected",
        "version": "4.2",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

31.3%

Related for CVELIST:CVE-2022-30625