Lucene search

K
nvd[email protected]NVD:CVE-2022-47027
HistoryApr 14, 2023 - 12:15 p.m.

CVE-2022-47027

2023-04-1412:15:07
CWE-22
web.nvd.nist.gov
timmystudios fast typing keyboard
dictionary traversal
arbitrary code execution
unauthorized apps
internal storage
file overwrite
cve-2022-47027

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.003

Percentile

65.3%

Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution.

Affected configurations

Nvd
Node
timmystudiosfast_typing_keyboardMatch1.275.1.162android
VendorProductVersionCPE
timmystudiosfast_typing_keyboard1.275.1.162cpe:2.3:a:timmystudios:fast_typing_keyboard:1.275.1.162:*:*:*:*:android:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.003

Percentile

65.3%

Related for NVD:CVE-2022-47027