Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3027

Опубликовано: 13 сент. 2022
Источник: nvd
CVSS3: 5.7
CVSS3: 5.7
EPSS Низкий

Описание

The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or display incorrect information.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:contechealth:cms8000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:contechealth:cms8000:-:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.0005
Низкий

5.7 Medium

CVSS3

5.7 Medium

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.7
github
больше 3 лет назад

The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or display incorrect information.

EPSS

Процентиль: 15%
0.0005
Низкий

5.7 Medium

CVSS3

5.7 Medium

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo