cvelist/2022/23xxx/CVE-2022-23768.json

87 lines
2.9 KiB
JSON
Raw Normal View History

2022-01-20 00:01:08 +00:00
{
"CVE_data_meta": {
2022-09-19 20:00:41 +00:00
"ASSIGNER": "vuln@krcert.or.kr",
2022-01-20 00:01:08 +00:00
"ID": "CVE-2022-23768",
2022-09-19 20:00:41 +00:00
"STATE": "PUBLIC",
"TITLE": "Neo Information Sys. NIS-HAP11AC remote access and manipulation vulnerability"
2022-01-20 00:01:08 +00:00
},
2022-09-19 20:00:41 +00:00
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Home AP NIS-HAP11AC",
"version": {
"version_data": [
{
"platform": "Windows, Android and etc.",
"version_affected": "=",
"version_value": "V3.0-B20201117095902"
}
]
}
}
]
},
"vendor_name": "Neo Information Systems Co., Ltd"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
2022-01-20 00:01:08 +00:00
"description": {
"description_data": [
{
"lang": "eng",
2022-09-19 20:00:41 +00:00
"value": "This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-284 Improper Access Control"
}
]
2022-01-20 00:01:08 +00:00
}
]
2022-09-19 20:00:41 +00:00
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"url": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66928",
"name": "https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66928"
}
]
},
"source": {
"discovery": "UNKNOWN"
2022-01-20 00:01:08 +00:00
}
}