XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges.
References
Configurations
Configuration 1 (hide)
|
History
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 |
19 Feb 2022, 04:17
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:broadcom:xcom_data_transport:11.6:*:*:*:*:windows:*:* cpe:2.3:a:broadcom:xcom_data_transport:11.6:*:*:*:*:linux:*:* cpe:2.3:a:broadcom:xcom_data_transport:11.6:*:*:*:*:unix:*:* |
|
References | (MISC) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/XCOM-Data-Transport---Windows-and-XCOM-Data-Transport--Linux--UNIX-Vulnerability-CVE-2022-23992/18750 - Permissions Required, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 10.0
v3 : 9.8 |
CWE | CWE-269 |
14 Feb 2022, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-02-14 22:15
Updated : 2024-02-04 22:29
NVD link : CVE-2022-23992
Mitre link : CVE-2022-23992
CVE.ORG link : CVE-2022-23992
JSON object : View
Products Affected
broadcom
- xcom_data_transport
CWE
CWE-20
Improper Input Validation