Lucene search

K
nvd[email protected]NVD:CVE-2022-35271
HistoryOct 25, 2022 - 5:15 p.m.

CVE-2022-35271

2022-10-2517:15:54
CWE-77
CWE-125
web.nvd.nist.gov
4
denial of service
robustel r1510
web server
cve-2022-35271
import cert file

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

36.8%

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of service is in the /action/import_cert_file/ API.

Affected configurations

Nvd
Node
robustelr1510_firmwareMatch3.1.16
OR
robustelr1510_firmwareMatch3.3.0
AND
robustelr1510Match-

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

36.8%

Related for NVD:CVE-2022-35271