{ "id": "CVE-2022-34906", "sourceIdentifier": "cve@mitre.org", "published": "2022-07-25T21:15:08.513", "lastModified": "2024-11-21T07:10:24.403", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests." }, { "lang": "es", "value": "Es usada una clave criptogr\u00e1fica embebida en FileWave versiones anteriores a 14.6.3 y versiones 14.7.x anteriores a 14.7.2. La explotaci\u00f3n podr\u00eda permitir a un actor no autenticado descifrar informaci\u00f3n confidencial guardada en FileWave, e incluso enviar peticiones dise\u00f1adas" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-798" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*", "versionEndExcluding": "14.6.3", "matchCriteriaId": "4BD1D697-DA49-4BBA-8EFF-399C15A604D8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*", "versionStartIncluding": "14.7.0", "versionEndExcluding": "14.7.2", "matchCriteriaId": "21A8FB0C-E92E-4228-AB45-D2E2EFE262B5" } ] } ] } ], "references": [ { "url": "https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/", "source": "cve@mitre.org", "tags": [ "Exploit", "Third Party Advisory" ] }, { "url": "https://kb.filewave.com/pages/viewpage.action?pageId=55544244", "source": "cve@mitre.org", "tags": [ "Release Notes", "Third Party Advisory" ] }, { "url": "https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit", "Third Party Advisory" ] }, { "url": "https://kb.filewave.com/pages/viewpage.action?pageId=55544244", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Release Notes", "Third Party Advisory" ] } ] }