CVE-2022-39031
Smart eVision - Exposure of Sensitive Information to an Unauthorized Actor -3
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
28 Sep 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit this vulnerability to acquire the Session IDs of other general users only.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Smart eVision Information Technology Inc. · Smart eVisionWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →