Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-22795

Опубликовано: 10 мар. 2022
Источник: nvd
CVSS3: 6.8
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the product is running with root on Linux systems and nt/authority on windows systems, which allows him to access and extract any file on the systems, such as passwd, shadow, hosts and so on. By gaining access to these files, attackers can steal sensitive information from the victims machine.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:signiant:manager\+agents:*:*:*:*:*:*:*:*
Версия до 13.5 (исключая)
cpe:2.3:a:signiant:manager\+agents:14.0:*:*:*:*:*:*:*
cpe:2.3:a:signiant:manager\+agents:15.0:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00244
Низкий

6.8 Medium

CVSS3

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 9.1
github
почти 4 года назад

Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the product is running with root on Linux systems and nt/authority on windows systems, which allows him to access and extract any file on the systems, such as passwd, shadow, hosts and so on. By gaining access to these files, attackers can steal sensitive information from the victims machine.

EPSS

Процентиль: 47%
0.00244
Низкий

6.8 Medium

CVSS3

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611
CWE-611