CVE-2022-28719
CVE-2022-28719
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 4.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
28 Apr 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.
Affected products
Hammock Corporation · AssetViewWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →