CVE-2022-36385 - CERT CVE
ID CVE-2022-36385
Sažetak A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load the firmware on any CMS8000 device.
Reference
CVSS
Base: 6.8
Impact: 5.9
Exploitability:0.9
Pristup
VektorSloženostAutentikacija
PHYSICAL LOW -
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 15-09-2022 - 17:27
Objavljeno 13-09-2022 - 15:15