Lucene search

K
cvelistKrcertCVELIST:CVE-2022-41157
HistoryNov 25, 2022 - 12:00 a.m.

CVE-2022-41157 ERP solution Remote Code Execution Vulnerability

2022-11-2500:00:00
CWE-798
krcert
www.cve.org
2
cve-2022-41157 erp solution remote code execution vulnerability
kyungrinara erp
system authority
sensitive information leakage
malicious commands

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

58.3%

A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands.

CNA Affected

[
  {
    "vendor": "Webcash Co.,Ltd",
    "product": "sERP Server 2.0",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "20.2.161",
        "status": "affected",
        "versionType": "custom"
      }
    ],
    "platforms": [
      "Windows"
    ]
  }
]

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

58.3%

Related for CVELIST:CVE-2022-41157