← volver
CVE-2022-3158

CVE-2022-3158

CVSS 8.8 HIGHEPSS 3.2%CWE-89
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 3.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
17 oct 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could allow a user with basic user privileges to perform remote code execution on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →