Lucene search

K
cvelistMitreCVELIST:CVE-2022-45194
HistoryNov 11, 2022 - 12:00 a.m.

CVE-2022-45194

2022-11-1100:00:00
mitre
www.cve.org
1
cbrn-analysis
xxe
vulnerability
ntlmv2-ssp
hash disclosure

CVSS3

3.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

AI Score

5.1

Confidence

High

EPSS

0.001

Percentile

31.3%

CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.

CVSS3

3.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

AI Score

5.1

Confidence

High

EPSS

0.001

Percentile

31.3%

Related for CVELIST:CVE-2022-45194