CWE-425
AllowedDirect Request ('Forced Browsing')
Abstraction: Base · Status: Incomplete
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
297 vulnerabilities reference this CWE, most recent first.
CVE-2023-2524 (GCVE-0-2023-2524)
Vulnerability from cvelistv5 – Published: 2023-05-04 18:31 – Updated: 2025-01-29 17:56- CWE-425 - Direct Request
| URL | Tags |
|---|---|
| https://vuldb.com/?id.228015 | vdb-entrytechnical-description |
| https://vuldb.com/?ctiid.228015 | signature |
| Vendor | Product | Version | |
|---|---|---|---|
| Control iD | RHiD |
Affected:
23.3.19.0
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T06:26:09.364Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"vdb-entry",
"technical-description",
"x_transferred"
],
"url": "https://vuldb.com/?id.228015"
},
{
"tags": [
"signature",
"x_transferred"
],
"url": "https://vuldb.com/?ctiid.228015"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-2524",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-01-29T17:56:49.180119Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-01-29T17:56:58.702Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "RHiD",
"vendor": "Control iD",
"versions": [
{
"status": "affected",
"version": "23.3.19.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "analyst",
"value": "Stux (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability classified as critical has been found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/#/. The manipulation leads to direct request. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-228015. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."
},
{
"lang": "de",
"value": "Es wurde eine Schwachstelle in Control iD RHiD 23.3.19.0 entdeckt. Sie wurde als kritisch eingestuft. Es betrifft eine unbekannte Funktion der Datei /v2/#/. Durch das Manipulieren mit unbekannten Daten kann eine direct request-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425 Direct Request",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-10-23T05:26:00.260Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/?id.228015"
},
{
"tags": [
"signature"
],
"url": "https://vuldb.com/?ctiid.228015"
}
],
"timeline": [
{
"lang": "en",
"time": "2023-05-04T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2023-05-04T00:00:00.000Z",
"value": "CVE reserved"
},
{
"lang": "en",
"time": "2023-05-04T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2023-05-27T16:04:42.000Z",
"value": "VulDB entry last update"
}
],
"title": "Control iD RHiD direct request"
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2023-2524",
"datePublished": "2023-05-04T18:31:03.558Z",
"dateReserved": "2023-05-04T16:21:42.872Z",
"dateUpdated": "2025-01-29T17:56:58.702Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-1699 (GCVE-0-2023-1699)
Vulnerability from cvelistv5 – Published: 2023-03-30 09:26 – Updated: 2025-02-11 20:12- CWE-425 - Direct Request ('Forced Browsing')
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:57:25.055Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://docs.rapid7.com/release-notes/nexpose/20230329/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-1699",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-02-11T20:12:05.970309Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-02-11T20:12:14.684Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Nexpose",
"vendor": "Rapid7",
"versions": [
{
"lessThanOrEqual": "6.6.186",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Casey Cooper"
}
],
"datePublic": "2023-03-29T08:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.\u0026nbsp; This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.\u0026nbsp;\u0026nbsp;"
}
],
"value": "Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.\u00a0 This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.\u00a0\u00a0"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425 Direct Request (\u0027Forced Browsing\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-03-30T09:26:13.515Z",
"orgId": "9974b330-7714-4307-a722-5648477acda7",
"shortName": "rapid7"
},
"references": [
{
"url": "https://docs.rapid7.com/release-notes/nexpose/20230329/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Rapid7 Nexpose Forced Browsing",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "9974b330-7714-4307-a722-5648477acda7",
"assignerShortName": "rapid7",
"cveId": "CVE-2023-1699",
"datePublished": "2023-03-30T09:26:13.515Z",
"dateReserved": "2023-03-29T14:17:15.354Z",
"dateUpdated": "2025-02-11T20:12:14.684Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-1682 (GCVE-0-2023-1682)
Vulnerability from cvelistv5 – Published: 2023-03-28 23:31 – Updated: 2024-08-02 05:57- CWE-425 - Direct Request
| URL | Tags |
|---|---|
| https://vuldb.com/?id.224239 | vdb-entrytechnical-description |
| https://vuldb.com/?ctiid.224239 | signaturepermissions-required |
| https://github.com/2714925725/CMS-bug/blob/main/I… | exploit |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:57:24.970Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"vdb-entry",
"technical-description",
"x_transferred"
],
"url": "https://vuldb.com/?id.224239"
},
{
"tags": [
"signature",
"permissions-required",
"x_transferred"
],
"url": "https://vuldb.com/?ctiid.224239"
},
{
"tags": [
"exploit",
"x_transferred"
],
"url": "https://github.com/2714925725/CMS-bug/blob/main/Informationdisclosure-1.md"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "CMS",
"vendor": "Xunrui",
"versions": [
{
"status": "affected",
"version": "4.61"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in Xunrui CMS 4.61 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dayrui/My/Config/Install.txt. The manipulation leads to direct request. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224239."
},
{
"lang": "de",
"value": "In Xunrui CMS 4.61 wurde eine Schwachstelle gefunden. Sie wurde als problematisch eingestuft. Hierbei betrifft es unbekannten Programmcode der Datei /dayrui/My/Config/Install.txt. Durch Manipulation mit unbekannten Daten kann eine direct request-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff \u00fcber das Netzwerk. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425 Direct Request",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-10-21T13:49:14.004Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/?id.224239"
},
{
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/?ctiid.224239"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/2714925725/CMS-bug/blob/main/Informationdisclosure-1.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2023-03-28T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2023-03-28T00:00:00.000Z",
"value": "CVE reserved"
},
{
"lang": "en",
"time": "2023-03-28T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2023-04-16T14:27:05.000Z",
"value": "VulDB entry last update"
}
],
"title": "Xunrui CMS Install.txt direct request"
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2023-1682",
"datePublished": "2023-03-28T23:31:05.404Z",
"dateReserved": "2023-03-28T20:20:52.813Z",
"dateUpdated": "2024-08-02T05:57:24.970Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-1663 (GCVE-0-2023-1663)
Vulnerability from cvelistv5 – Published: 2023-03-29 13:16 – Updated: 2025-02-12 16:19- CWE-425 - Direct Request ('Forced Browsing')
| URL | Tags |
|---|---|
| https://community.synopsys.com/s/article/SIG-Prod… | vendor-advisory |
| https://community.synopsys.com/s/article/Mitigati… | mitigation |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:57:24.229Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://community.synopsys.com/s/article/SIG-Product-Security-Advisory-CVE-2023-1663-Affecting-Coverity-Platform"
},
{
"tags": [
"mitigation",
"x_transferred"
],
"url": "https://community.synopsys.com/s/article/Mitigation-for-Coverity-Platforms-Exposure-to-CVE-2023-1663"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-1663",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-02-12T16:18:31.426850Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-02-12T16:19:38.925Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Coverity",
"vendor": "Synopsys",
"versions": [
{
"lessThanOrEqual": "2023.3.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Juha Leivo"
}
],
"datePublic": "2023-03-29T13:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible.\u0026nbsp;5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)"
}
],
"value": "Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible.\u00a05.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)"
}
],
"impacts": [
{
"capecId": "CAPEC-87",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-87 Forceful Browsing"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425 Direct Request (\u0027Forced Browsing\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-03-29T13:16:40.269Z",
"orgId": "8cad7728-009c-4a3d-a95e-ca62e6ff8a0b",
"shortName": "SNPS"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://community.synopsys.com/s/article/SIG-Product-Security-Advisory-CVE-2023-1663-Affecting-Coverity-Platform"
},
{
"tags": [
"mitigation"
],
"url": "https://community.synopsys.com/s/article/Mitigation-for-Coverity-Platforms-Exposure-to-CVE-2023-1663"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Authenticated Resources Accessible via Forced Browsing",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "8cad7728-009c-4a3d-a95e-ca62e6ff8a0b",
"assignerShortName": "SNPS",
"cveId": "CVE-2023-1663",
"datePublished": "2023-03-29T13:16:40.269Z",
"dateReserved": "2023-03-27T16:21:21.908Z",
"dateUpdated": "2025-02-12T16:19:38.925Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-31485 (GCVE-0-2022-31485)
Vulnerability from cvelistv5 – Published: 2022-06-06 16:41 – Updated: 2024-09-17 00:26- CWE-425 - Direct Request (Forced Browsing)
| URL | Tags |
|---|---|
| https://www.corporate.carrier.com/product-securit… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| LenelS2 | LNL-X2210 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | LNL-X2220 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | LNL-X3300 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | LNL-X4420 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | LNL-4420 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | S2-LP-1501 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | S2-LP-1502 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | S2-LP-2500 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | S2-LP-4502 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | LP1501 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | LP1502 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | LP2500 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | LP4502 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | EP4502 |
Affected:
ALL , < 1.29
(custom)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T07:19:06.061Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "LNL-X2210",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-X2220",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-X3300",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-X4420",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-4420",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-1501",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-1502",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-2500",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-4502",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP1501",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP1502",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP2500",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP4502",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "EP4502",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Sam Quinn @eAyeP and Steve Povolny @spovolny from Trellix Threat Labs"
}
],
"datePublic": "2022-06-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated attacker can send a specially crafted packets to update the \u201cnotes\u201d section of the home page of the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425 Direct Request (Forced Browsing)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-06-06T16:41:09.000Z",
"orgId": "e24e6442-3ae1-4538-a7b8-7ac95586db8f",
"shortName": "Carrier"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/"
}
],
"solutions": [
{
"lang": "en",
"value": "Update to the latest version of firmware"
}
],
"source": {
"advisory": "CARR-PSA-006-0522",
"discovery": "EXTERNAL"
},
"title": "Unauthenticated homepage note modification",
"workarounds": [
{
"lang": "en",
"value": "Disable the controller\u0027s Web Server. \nWhen the controller is configured to disable web access, you cannot remotely login into the controller\u2019s web page.\n1. Login to controller web pages\n2. Go to \u201cUsers\u201d Tab\n3. Near bottom of the Users page, check option to \u201cDisable Web Server\u201d\n4. Then select \u201cSubmit\u201d at the bottom of the page\n5. Then select \u201cApply Settings\u201d tab\n6. And on that page, select button \u201cApply Settings, Reboot\u201d\nThe Controller will apply the new setting and reboot. Web login will be disabled until switch 1 is physically turned ON, on the controller."
}
],
"x_generator": {
"engine": "Vulnogram 0.0.9"
},
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "productsecurity@carrier.com",
"DATE_PUBLIC": "2022-06-02T22:00:00.000Z",
"ID": "CVE-2022-31485",
"STATE": "PUBLIC",
"TITLE": "Unauthenticated homepage note modification"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "LNL-X2210",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LNL-X2220",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LNL-X3300",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LNL-X4420",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LNL-4420",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "S2-LP-1501",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "S2-LP-1502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "S2-LP-2500",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "S2-LP-4502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
}
]
},
"vendor_name": "LenelS2"
},
{
"product": {
"product_data": [
{
"product_name": "LP1501",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LP1502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LP2500",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LP4502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "EP4502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
}
]
},
"vendor_name": "HID Mercury"
}
]
}
},
"credit": [
{
"lang": "eng",
"value": "Sam Quinn @eAyeP and Steve Povolny @spovolny from Trellix Threat Labs"
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "An unauthenticated attacker can send a specially crafted packets to update the \u201cnotes\u201d section of the home page of the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-425 Direct Request (Forced Browsing)"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.corporate.carrier.com/product-security/advisories-resources/",
"refsource": "MISC",
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/"
}
]
},
"solution": [
{
"lang": "en",
"value": "Update to the latest version of firmware"
}
],
"source": {
"advisory": "CARR-PSA-006-0522",
"discovery": "EXTERNAL"
},
"work_around": [
{
"lang": "en",
"value": "Disable the controller\u0027s Web Server. \nWhen the controller is configured to disable web access, you cannot remotely login into the controller\u2019s web page.\n1. Login to controller web pages\n2. Go to \u201cUsers\u201d Tab\n3. Near bottom of the Users page, check option to \u201cDisable Web Server\u201d\n4. Then select \u201cSubmit\u201d at the bottom of the page\n5. Then select \u201cApply Settings\u201d tab\n6. And on that page, select button \u201cApply Settings, Reboot\u201d\nThe Controller will apply the new setting and reboot. Web login will be disabled until switch 1 is physically turned ON, on the controller."
}
]
}
}
},
"cveMetadata": {
"assignerOrgId": "e24e6442-3ae1-4538-a7b8-7ac95586db8f",
"assignerShortName": "Carrier",
"cveId": "CVE-2022-31485",
"datePublished": "2022-06-06T16:41:09.100Z",
"dateReserved": "2022-05-23T00:00:00.000Z",
"dateUpdated": "2024-09-17T00:26:24.486Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-31484 (GCVE-0-2022-31484)
Vulnerability from cvelistv5 – Published: 2022-06-06 16:40 – Updated: 2024-09-17 01:37- CWE-425 - Direct Request (Forced Browsing)
| URL | Tags |
|---|---|
| https://www.corporate.carrier.com/product-securit… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| LenelS2 | LNL-X2210 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | LNL-X2220 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | LNL-X3300 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | LNL-X4420 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | LNL-4420 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | S2-LP-1501 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | S2-LP-1502 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | S2-LP-2500 |
Affected:
ALL , < 1.29
(custom)
|
|
| LenelS2 | S2-LP-4502 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | LP1501 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | LP1502 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | LP2500 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | LP4502 |
Affected:
ALL , < 1.29
(custom)
|
|
| HID Mercury | EP4502 |
Affected:
ALL , < 1.29
(custom)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T07:19:06.059Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "LNL-X2210",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-X2220",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-X3300",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-X4420",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-4420",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-1501",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-1502",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-2500",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-4502",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP1501",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP1502",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP2500",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP4502",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "EP4502",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.29",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Sam Quinn @eAyeP and Steve Povolny @spovolny from Trellix Threat Labs"
}
],
"datePublic": "2022-06-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The impact of this vulnerability is that an unauthenticated attacker could restrict access to the web interface to legitimate users and potentially requiring them to use the default user dip switch procedure to gain access back."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425 Direct Request (Forced Browsing)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-06-06T16:40:33.000Z",
"orgId": "e24e6442-3ae1-4538-a7b8-7ac95586db8f",
"shortName": "Carrier"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/"
}
],
"solutions": [
{
"lang": "en",
"value": "Update to the latest version of firmware"
}
],
"source": {
"advisory": "CARR-PSA-006-0522",
"discovery": "EXTERNAL"
},
"title": "User Account Deletion Unauthenticated",
"workarounds": [
{
"lang": "en",
"value": "Disable the controller\u0027s Web Server. \nWhen the controller is configured to disable web access, you cannot remotely login into the controller\u2019s web page.\n1. Login to controller web pages\n2. Go to \u201cUsers\u201d Tab\n3. Near bottom of the Users page, check option to \u201cDisable Web Server\u201d\n4. Then select \u201cSubmit\u201d at the bottom of the page\n5. Then select \u201cApply Settings\u201d tab\n6. And on that page, select button \u201cApply Settings, Reboot\u201d\nThe Controller will apply the new setting and reboot. Web login will be disabled until switch 1 is physically turned ON, on the controller."
}
],
"x_generator": {
"engine": "Vulnogram 0.0.9"
},
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "productsecurity@carrier.com",
"DATE_PUBLIC": "2022-06-02T22:00:00.000Z",
"ID": "CVE-2022-31484",
"STATE": "PUBLIC",
"TITLE": "User Account Deletion Unauthenticated"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "LNL-X2210",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LNL-X2220",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LNL-X3300",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LNL-X4420",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LNL-4420",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "S2-LP-1501",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "S2-LP-1502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "S2-LP-2500",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "S2-LP-4502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
}
]
},
"vendor_name": "LenelS2"
},
{
"product": {
"product_data": [
{
"product_name": "LP1501",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LP1502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LP2500",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "LP4502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
},
{
"product_name": "EP4502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.29"
}
]
}
}
]
},
"vendor_name": "HID Mercury"
}
]
}
},
"credit": [
{
"lang": "eng",
"value": "Sam Quinn @eAyeP and Steve Povolny @spovolny from Trellix Threat Labs"
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The impact of this vulnerability is that an unauthenticated attacker could restrict access to the web interface to legitimate users and potentially requiring them to use the default user dip switch procedure to gain access back."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-425 Direct Request (Forced Browsing)"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.corporate.carrier.com/product-security/advisories-resources/",
"refsource": "MISC",
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/"
}
]
},
"solution": [
{
"lang": "en",
"value": "Update to the latest version of firmware"
}
],
"source": {
"advisory": "CARR-PSA-006-0522",
"discovery": "EXTERNAL"
},
"work_around": [
{
"lang": "en",
"value": "Disable the controller\u0027s Web Server. \nWhen the controller is configured to disable web access, you cannot remotely login into the controller\u2019s web page.\n1. Login to controller web pages\n2. Go to \u201cUsers\u201d Tab\n3. Near bottom of the Users page, check option to \u201cDisable Web Server\u201d\n4. Then select \u201cSubmit\u201d at the bottom of the page\n5. Then select \u201cApply Settings\u201d tab\n6. And on that page, select button \u201cApply Settings, Reboot\u201d\nThe Controller will apply the new setting and reboot. Web login will be disabled until switch 1 is physically turned ON, on the controller."
}
]
}
}
},
"cveMetadata": {
"assignerOrgId": "e24e6442-3ae1-4538-a7b8-7ac95586db8f",
"assignerShortName": "Carrier",
"cveId": "CVE-2022-31484",
"datePublished": "2022-06-06T16:40:33.983Z",
"dateReserved": "2022-05-23T00:00:00.000Z",
"dateUpdated": "2024-09-17T01:37:06.347Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-31480 (GCVE-0-2022-31480)
Vulnerability from cvelistv5 – Published: 2022-06-06 16:37 – Updated: 2024-09-17 01:55- CWE-425 - Direct Request (Forced Browsing)
| URL | Tags |
|---|---|
| https://www.corporate.carrier.com/product-securit… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| LenelS2 | LNL-X2210 |
Affected:
ALL , < 1.302
(custom)
|
|
| LenelS2 | LNL-X2220 |
Affected:
ALL , < 1.302
(custom)
|
|
| LenelS2 | LNL-X3300 |
Affected:
ALL , < 1.302
(custom)
|
|
| LenelS2 | LNL-X4420 |
Affected:
ALL , < 1.302
(custom)
|
|
| LenelS2 | LNL-4420 |
Affected:
ALL , < 1.296
(custom)
|
|
| LenelS2 | S2-LP-1501 |
Affected:
ALL , < 1.302
(custom)
|
|
| LenelS2 | S2-LP-1502 |
Affected:
ALL , < 1.302
(custom)
|
|
| LenelS2 | S2-LP-2500 |
Affected:
ALL , < 1.302
(custom)
|
|
| LenelS2 | S2-LP-4502 |
Affected:
ALL , < 1.302
(custom)
|
|
| HID Mercury | LP1501 |
Affected:
ALL , < 1.302
(custom)
|
|
| HID Mercury | LP1502 |
Affected:
ALL , < 1.302
(custom)
|
|
| HID Mercury | LP2500 |
Affected:
ALL , < 1.302
(custom)
|
|
| HID Mercury | LP4502 |
Affected:
ALL , < 1.302
(custom)
|
|
| HID Mercury | EP4502 |
Affected:
ALL , < 1.296
(custom)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T07:19:06.075Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "LNL-X2210",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-X2220",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-X3300",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-X4420",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LNL-4420",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.296",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-1501",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-1502",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-2500",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "S2-LP-4502",
"vendor": "LenelS2",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP1501",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP1502",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP2500",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "LP4502",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.302",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
},
{
"product": "EP4502",
"vendor": "HID Mercury",
"versions": [
{
"lessThan": "1.296",
"status": "affected",
"version": "ALL",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Sam Quinn @eAyeP and Steve Povolny @spovolny from Trellix Threat Labs"
}
],
"datePublic": "2022-06-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The attacker needs to have a properly signed and encrypted binary, loading the firmware to the device ultimately triggers a reboot."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425 Direct Request (Forced Browsing)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-06-06T16:37:36.000Z",
"orgId": "e24e6442-3ae1-4538-a7b8-7ac95586db8f",
"shortName": "Carrier"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/"
}
],
"solutions": [
{
"lang": "en",
"value": "Update to the latest version of firmware"
}
],
"source": {
"advisory": "CARR-PSA-006-0522",
"discovery": "EXTERNAL"
},
"title": "Unauthenticated Firmware Upload and Arbitrary Reboot",
"workarounds": [
{
"lang": "en",
"value": "Disable the controller\u0027s Web Server. \nWhen the controller is configured to disable web access, you cannot remotely login into the controller\u2019s web page.\n1. Login to controller web pages\n2. Go to \u201cUsers\u201d Tab\n3. Near bottom of the Users page, check option to \u201cDisable Web Server\u201d\n4. Then select \u201cSubmit\u201d at the bottom of the page\n5. Then select \u201cApply Settings\u201d tab\n6. And on that page, select button \u201cApply Settings, Reboot\u201d\nThe Controller will apply the new setting and reboot. Web login will be disabled until switch 1 is physically turned ON, on the controller."
}
],
"x_generator": {
"engine": "Vulnogram 0.0.9"
},
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "productsecurity@carrier.com",
"DATE_PUBLIC": "2022-06-02T22:00:00.000Z",
"ID": "CVE-2022-31480",
"STATE": "PUBLIC",
"TITLE": "Unauthenticated Firmware Upload and Arbitrary Reboot"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "LNL-X2210",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "LNL-X2220",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "LNL-X3300",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "LNL-X4420",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "LNL-4420",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.296"
}
]
}
},
{
"product_name": "S2-LP-1501",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "S2-LP-1502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "S2-LP-2500",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "S2-LP-4502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
}
]
},
"vendor_name": "LenelS2"
},
{
"product": {
"product_data": [
{
"product_name": "LP1501",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "LP1502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "LP2500",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "LP4502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.302"
}
]
}
},
{
"product_name": "EP4502",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "ALL",
"version_value": "1.296"
}
]
}
}
]
},
"vendor_name": "HID Mercury"
}
]
}
},
"credit": [
{
"lang": "eng",
"value": "Sam Quinn @eAyeP and Steve Povolny @spovolny from Trellix Threat Labs"
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The attacker needs to have a properly signed and encrypted binary, loading the firmware to the device ultimately triggers a reboot."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-425 Direct Request (Forced Browsing)"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.corporate.carrier.com/product-security/advisories-resources/",
"refsource": "MISC",
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/"
}
]
},
"solution": [
{
"lang": "en",
"value": "Update to the latest version of firmware"
}
],
"source": {
"advisory": "CARR-PSA-006-0522",
"discovery": "EXTERNAL"
},
"work_around": [
{
"lang": "en",
"value": "Disable the controller\u0027s Web Server. \nWhen the controller is configured to disable web access, you cannot remotely login into the controller\u2019s web page.\n1. Login to controller web pages\n2. Go to \u201cUsers\u201d Tab\n3. Near bottom of the Users page, check option to \u201cDisable Web Server\u201d\n4. Then select \u201cSubmit\u201d at the bottom of the page\n5. Then select \u201cApply Settings\u201d tab\n6. And on that page, select button \u201cApply Settings, Reboot\u201d\nThe Controller will apply the new setting and reboot. Web login will be disabled until switch 1 is physically turned ON, on the controller."
}
]
}
}
},
"cveMetadata": {
"assignerOrgId": "e24e6442-3ae1-4538-a7b8-7ac95586db8f",
"assignerShortName": "Carrier",
"cveId": "CVE-2022-31480",
"datePublished": "2022-06-06T16:37:36.175Z",
"dateReserved": "2022-05-23T00:00:00.000Z",
"dateUpdated": "2024-09-17T01:55:48.654Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-29238 (GCVE-0-2022-29238)
Vulnerability from cvelistv5 – Published: 2022-06-14 17:55 – Updated: 2025-04-23 18:16- CWE-425 - Direct Request ('Forced Browsing')
| URL | Tags |
|---|---|
| https://github.com/jupyter/notebook/security/advi… | x_refsource_CONFIRM |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T06:17:54.257Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://github.com/jupyter/notebook/security/advisories/GHSA-v7vq-3x77-87vg"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2022-29238",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-23T14:05:26.708258Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-04-23T18:16:17.365Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "notebook",
"vendor": "jupyter",
"versions": [
{
"status": "affected",
"version": "\u003c 6.4.12"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the notebook server with `ContentsManager.allow_hidden = False` only prevented listing the contents of hidden directories, not accessing individual hidden files or files in hidden directories (i.e. hidden files were \u0027hidden\u0027 but not \u0027inaccessible\u0027). This could lead to notebook configurations allowing authenticated access to files that may reasonably be expected to be disallowed. Because fully authenticated requests are required, this is of relatively low impact. But if a server\u0027s root directory contains sensitive files whose only protection from the server is being hidden (e.g. `~/.ssh` while serving $HOME), then any authenticated requests could access files if their names are guessable. Such contexts also necessarily have full access to the server and therefore execution permissions, which also generally grants access to all the same files. So this does not generally result in any privilege escalation or increase in information access, only an additional, unintended means by which the files could be accessed. Version 6.4.12 contains a patch for this issue. There are currently no known workarounds."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425: Direct Request (\u0027Forced Browsing\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-06-14T17:55:10.000Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/jupyter/notebook/security/advisories/GHSA-v7vq-3x77-87vg"
}
],
"source": {
"advisory": "GHSA-v7vq-3x77-87vg",
"discovery": "UNKNOWN"
},
"title": "Forced Browsing in Jupyter Notebook",
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "security-advisories@github.com",
"ID": "CVE-2022-29238",
"STATE": "PUBLIC",
"TITLE": "Forced Browsing in Jupyter Notebook"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "notebook",
"version": {
"version_data": [
{
"version_value": "\u003c 6.4.12"
}
]
}
}
]
},
"vendor_name": "jupyter"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the notebook server with `ContentsManager.allow_hidden = False` only prevented listing the contents of hidden directories, not accessing individual hidden files or files in hidden directories (i.e. hidden files were \u0027hidden\u0027 but not \u0027inaccessible\u0027). This could lead to notebook configurations allowing authenticated access to files that may reasonably be expected to be disallowed. Because fully authenticated requests are required, this is of relatively low impact. But if a server\u0027s root directory contains sensitive files whose only protection from the server is being hidden (e.g. `~/.ssh` while serving $HOME), then any authenticated requests could access files if their names are guessable. Such contexts also necessarily have full access to the server and therefore execution permissions, which also generally grants access to all the same files. So this does not generally result in any privilege escalation or increase in information access, only an additional, unintended means by which the files could be accessed. Version 6.4.12 contains a patch for this issue. There are currently no known workarounds."
}
]
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-425: Direct Request (\u0027Forced Browsing\u0027)"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://github.com/jupyter/notebook/security/advisories/GHSA-v7vq-3x77-87vg",
"refsource": "CONFIRM",
"url": "https://github.com/jupyter/notebook/security/advisories/GHSA-v7vq-3x77-87vg"
}
]
},
"source": {
"advisory": "GHSA-v7vq-3x77-87vg",
"discovery": "UNKNOWN"
}
}
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2022-29238",
"datePublished": "2022-06-14T17:55:10.000Z",
"dateReserved": "2022-04-13T00:00:00.000Z",
"dateUpdated": "2025-04-23T18:16:17.365Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-24385 (GCVE-0-2022-24385)
Vulnerability from cvelistv5 – Published: 2022-03-14 00:00 – Updated: 2025-03-11 13:40- CWE-425 - Direct Request (Forced Browsing)
| URL | Tags |
|---|---|
| https://csirt.divd.nl/DIVD-2021-00029 | x_refsource_CONFIRMrelated |
| https://csirt.divd.nl/CVE-2022-24385 | x_refsource_CONFIRMthird-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| SmarterTools | SmarterTrack |
Affected:
100.x , < Build 8075
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2022-24385",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-24T14:13:03.172916Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T17:15:56.475Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-03T04:07:02.545Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM",
"related",
"x_transferred"
],
"url": "https://csirt.divd.nl/DIVD-2021-00029"
},
{
"tags": [
"x_refsource_CONFIRM",
"third-party-advisory",
"x_transferred"
],
"url": "https://csirt.divd.nl/CVE-2022-24385"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "SmarterTrack",
"vendor": "SmarterTools",
"versions": [
{
"lessThan": "Build 8075",
"status": "affected",
"version": "100.x",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Wietse Boonstra (DIVD)"
},
{
"lang": "en",
"type": "analyst",
"value": "Finn van der Knaap (DIVD)"
},
{
"lang": "en",
"type": "analyst",
"value": "Victor Gevers (DIVD)"
}
],
"datePublic": "2022-03-11T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425 Direct Request (Forced Browsing)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-03-11T13:40:44.472Z",
"orgId": "b87402ff-ae37-4194-9dae-31abdbd6f217",
"shortName": "DIVD"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM",
"related"
],
"url": "https://csirt.divd.nl/DIVD-2021-00029"
},
{
"tags": [
"x_refsource_CONFIRM",
"third-party-advisory"
],
"url": "https://csirt.divd.nl/CVE-2022-24385"
}
],
"source": {
"advisory": "DIVD-2021-00029",
"discovery": "INTERNAL"
},
"title": "Information disclosure via direct object access on SmarterTrack v100.0.8019.14010",
"x_generator": {
"engine": "Vulnogram 0.0.9"
}
}
},
"cveMetadata": {
"assignerOrgId": "b87402ff-ae37-4194-9dae-31abdbd6f217",
"assignerShortName": "DIVD",
"cveId": "CVE-2022-24385",
"datePublished": "2022-03-14T00:00:00.000Z",
"dateReserved": "2022-02-03T00:00:00.000Z",
"dateUpdated": "2025-03-11T13:40:44.472Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-2551 (GCVE-0-2022-2551)
Vulnerability from cvelistv5 – Published: 2022-08-22 15:03 – Updated: 2024-08-03 00:39- CWE-425 - Direct Request ('Forced Browsing')
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/f27d753e-861a-4d… | x_refsource_MISC |
| https://github.com/SecuriTrust/CVEsLab/tree/main/… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Duplicator – WordPress Migration Plugin |
Affected:
1.4.7 , < 1.4.7
(custom)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T00:39:08.049Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://wpscan.com/vulnerability/f27d753e-861a-4d8d-9b9a-6c99a8a7ebe0"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/SecuriTrust/CVEsLab/tree/main/CVE-2022-2551"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Duplicator \u2013 WordPress Migration Plugin",
"vendor": "Unknown",
"versions": [
{
"lessThan": "1.4.7",
"status": "affected",
"version": "1.4.7",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Ihsan Sencan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-425",
"description": "CWE-425 Direct Request (\u0027Forced Browsing\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-08-22T15:03:52.000Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://wpscan.com/vulnerability/f27d753e-861a-4d8d-9b9a-6c99a8a7ebe0"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/SecuriTrust/CVEsLab/tree/main/CVE-2022-2551"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Duplicator \u003c 1.4.7 - Unauthenticated Backup Download",
"x_generator": "WPScan CVE Generator",
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "contact@wpscan.com",
"ID": "CVE-2022-2551",
"STATE": "PUBLIC",
"TITLE": "Duplicator \u003c 1.4.7 - Unauthenticated Backup Download"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Duplicator \u2013 WordPress Migration Plugin",
"version": {
"version_data": [
{
"version_affected": "\u003c",
"version_name": "1.4.7",
"version_value": "1.4.7"
}
]
}
}
]
},
"vendor_name": "Unknown"
}
]
}
},
"credit": [
{
"lang": "eng",
"value": "Ihsan Sencan"
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating."
}
]
},
"generator": "WPScan CVE Generator",
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-425 Direct Request (\u0027Forced Browsing\u0027)"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://wpscan.com/vulnerability/f27d753e-861a-4d8d-9b9a-6c99a8a7ebe0",
"refsource": "MISC",
"url": "https://wpscan.com/vulnerability/f27d753e-861a-4d8d-9b9a-6c99a8a7ebe0"
},
{
"name": "https://github.com/SecuriTrust/CVEsLab/tree/main/CVE-2022-2551",
"refsource": "MISC",
"url": "https://github.com/SecuriTrust/CVEsLab/tree/main/CVE-2022-2551"
}
]
},
"source": {
"discovery": "EXTERNAL"
}
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2022-2551",
"datePublished": "2022-08-22T15:03:52.000Z",
"dateReserved": "2022-07-27T00:00:00.000Z",
"dateUpdated": "2024-08-03T00:39:08.049Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
Mitigation
Apply appropriate access control authorizations for each access to all restricted URLs, scripts or files.
Mitigation
Consider using MVC based frameworks such as Struts.
CAPEC-127: Directory Indexing
An adversary crafts a request to a target that results in the target listing/indexing the content of a directory as output. One common method of triggering directory contents as output is to construct a request containing a path that terminates in a directory name rather than a file name since many applications are configured to provide a list of the directory's contents when such a request is received. An adversary can use this to explore the directory tree on a target as well as learn the names of files. This can often end up revealing test files, backup files, temporary files, hidden files, configuration files, user accounts, script contents, as well as naming conventions, all of which can be used by an attacker to mount additional attacks.
CAPEC-143: Detect Unpublicized Web Pages
An adversary searches a targeted web site for web pages that have not been publicized. In doing this, the adversary may be able to gain access to information that the targeted site did not intend to make public.
CAPEC-144: Detect Unpublicized Web Services
An adversary searches a targeted web site for web services that have not been publicized. This attack can be especially dangerous since unpublished but available services may not have adequate security controls placed upon them given that an administrator may believe they are unreachable.
CAPEC-668: Key Negotiation of Bluetooth Attack (KNOB)
An adversary can exploit a flaw in Bluetooth key negotiation allowing them to decrypt information sent between two devices communicating via Bluetooth. The adversary uses an Adversary in the Middle setup to modify packets sent between the two devices during the authentication process, specifically the entropy bits. Knowledge of the number of entropy bits will allow the attacker to easily decrypt information passing over the line of communication.
CAPEC-87: Forceful Browsing
An attacker employs forceful browsing (direct URL entry) to access portions of a website that are otherwise unreachable. Usually, a front controller or similar design pattern is employed to protect access to portions of a web application. Forceful browsing enables an attacker to access information, perform privileged operations and otherwise reach sections of the web application that have been improperly protected.