CVE-2022-29860:
A heap overflow vulnerability in the TLS communication of the management web interface. The feature is on by default and the vulnerability can be exploited over the network to gain remote code execution with no user interaction.
Score
A numerical rating that indicates how dangerous this vulnerability is.
9.8CriticalA numerical rating that indicates how dangerous this vulnerability is.
- Published Date:May 1, 2022
- CISA KEV Date:*No Data*
- Industries Affected:20
Exploitability
- Attack Vector:NETWORK
- Attack Complexity:LOW
- Privileges Required:NONE
- User Interaction:NONE
- Scope:UNCHANGED
Impact
- Confidentiality Impact:HIGH
- Integrity Impact:HIGH
- Availability Impact:HIGH
Description Preview
A heap overflow vulnerability in the TLS communication of the management web interface. The feature is on by default and the vulnerability can be exploited over the network to gain remote code execution with no user interaction.
Industries Affected
Below is a list of industries most commonly impacted or potentially at risk based on intelligence.
Low