Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-35217

Опубликовано: 02 авг. 2022
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:nhi:health_insurance_web_service_component:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.00067
Низкий

7.8 High

CVSS3

Дефекты

CWE-787
CWE-787

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.

EPSS

Процентиль: 21%
0.00067
Низкий

7.8 High

CVSS3

Дефекты

CWE-787
CWE-787