Lucene search

K
vulnrichmentINCIBEVULNRICHMENT:CVE-2022-4896
HistorySep 12, 2023 - 7:22 a.m.

CVE-2022-4896

2023-09-1207:22:31
CWE-400
INCIBE
github.com
cyber control
version 1.650
vulnerability
pop-up window
denial of service

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

AI Score

6.9

Confidence

High

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Cyber Control, in its 1.650 version, is affected by a vulnerabilityΒ in the generation on the server of pop-up windows with the messages β€œPNTMEDIDAS”, β€œPEDIR”, β€œHAYDISCOA” or β€œSPOOLER”. A complete denial of service can be achieved by sending multiple requests simultaneously on a core.

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

AI Score

6.9

Confidence

High

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Related for VULNRICHMENT:CVE-2022-4896