VulnerabilityModified
CVE-2022-39031
An unauthorized remote attacker can exploit this vulnerability to acquire the Session IDs of other general users only.
MEDIUM 5.3EPSS 0.64%
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit this vulnerability to acquire the Session IDs of other general users only.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-863
- Affected
- lcnet/smart evision
- Source
- twcert@cert.org.tw
References
- https://www.twcert.org.tw/tw/cp-132-6568-331c1-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-6568-331c1-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.