Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-28944

Опубликовано: 23 мая 2022
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Средний

Описание

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:emcosoftware:msi_package_builder:9.1.4:*:*:*:*:*:*:*
cpe:2.3:a:emcosoftware:network_inventory:5.8.22:*:*:*:*:*:*:*
cpe:2.3:a:emcosoftware:network_software_scanner:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:emcosoftware:ping_monitor:8.0.18:*:*:*:*:*:*:*
cpe:2.3:a:emcosoftware:remote_installer:6.0.13:*:*:*:*:*:*:*
cpe:2.3:a:emcosoftware:remote_shutdown:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:emcosoftware:unlock_it:6.1.1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:emcosoftware:wakeonlan:2.0.8:*:*:*:free:*:*:*
cpe:2.3:a:emcosoftware:wakeonlan:2.0.8:*:*:*:professional:*:*:*

EPSS

Процентиль: 93%
0.10874
Средний

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.

CVSS3: 8.8
fstec
почти 3 года назад

Уязвимость компонента Live Update Wizard программных продуктов EMCO, связанная с возможностью загрузки кода без проверки его целостности. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код

EPSS

Процентиль: 93%
0.10874
Средний

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-494