Lucene search

K
nvd[email protected]NVD:CVE-2022-41157
HistoryNov 25, 2022 - 7:15 p.m.

CVE-2022-41157

2022-11-2519:15:11
CWE-798
web.nvd.nist.gov
1
cve-2022-41157
kyungrinara
erp solution
fixed password
system authority
sensitive information
malicious commands

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.3%

A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands.

Affected configurations

Nvd
Node
microsoftwindowsMatch-
AND
webcashserp_server_2.0Range<20.2.161
VendorProductVersionCPE
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
webcashserp_server_2.0*cpe:2.3:a:webcash:serp_server_2.0:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.3%

Related for NVD:CVE-2022-41157