Lucene search

K
nvd[email protected]NVD:CVE-2022-38355
HistoryDec 13, 2022 - 10:15 p.m.

CVE-2022-38355

2022-12-1322:15:10
CWE-284
web.nvd.nist.gov
1
daikin
svmpc1
svmpc2
lan
unauthenticated
sensitive information
vulnerability

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

10.6%

Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to

attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication.

Affected configurations

Nvd
Node
daikinlatamsvmpc1Range2.1.22
OR
daikinlatamsvmpc2Range1.2.3
VendorProductVersionCPE
daikinlatamsvmpc1*cpe:2.3:a:daikinlatam:svmpc1:*:*:*:*:*:*:*:*
daikinlatamsvmpc2*cpe:2.3:a:daikinlatam:svmpc2:*:*:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

10.6%

Related for NVD:CVE-2022-38355