Vulnerability Description
RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perform arbitrary system command and disrupt service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Changingtec | Rava Certificate Validation System | 3 |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-6618-11fd8-1.htmlThird Party AdvisoryVDB Entry
- https://www.twcert.org.tw/tw/cp-132-6618-11fd8-1.htmlThird Party AdvisoryVDB Entry
FAQ
What is CVE-2022-39057?
CVE-2022-39057 is a vulnerability with a CVSS score of 7.2 (HIGH). RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perfor...
How severe is CVE-2022-39057?
CVE-2022-39057 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-39057?
Check the references section above for vendor advisories and patch information. Affected products include: Changingtec Rava Certificate Validation System.