cvelist/2022/2xxx/CVE-2022-2661.json

99 lines
3.4 KiB
JSON
Raw Normal View History

2022-08-04 15:00:52 +00:00
{
"CVE_data_meta": {
2022-08-16 20:01:17 +00:00
"ASSIGNER": "ics-cert@hq.dhs.gov",
"DATE_PUBLIC": "2022-08-16T17:26:00.000Z",
2022-08-04 15:00:52 +00:00
"ID": "CVE-2022-2661",
2022-08-16 20:01:17 +00:00
"STATE": "PUBLIC",
"TITLE": "Sequi PortBloque S Improper Authorization"
2022-08-04 15:00:52 +00:00
},
2022-08-16 20:01:17 +00:00
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "PortBloque S",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "All"
}
]
}
}
]
},
"vendor_name": "Sequi"
}
]
}
},
"credit": [
{
"lang": "eng",
"value": "Byron Chaney of Accenture Security reported these vulnerabilities to CISA."
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
2022-08-04 15:00:52 +00:00
"description": {
"description_data": [
{
"lang": "eng",
2022-08-16 20:01:17 +00:00
"value": "Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using specifically crafted requests."
2022-08-04 15:00:52 +00:00
}
]
2022-08-16 20:01:17 +00:00
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-285 Improper Authorization"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-07",
"name": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-07"
}
]
},
"source": {
"discovery": "UNKNOWN"
},
"work_around": [
{
"lang": "eng",
"value": "Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the Internet.\nLocate control system networks and remote devices behind firewalls and isolate them from business networks.\nWhen remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as its connected devices."
}
]
2022-08-04 15:00:52 +00:00
}