CVE-2022-34906

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*
cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*

History

02 Aug 2022, 16:36

Type Values Removed Values Added
CWE CWE-798
CPE cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://kb.filewave.com/pages/viewpage.action?pageId=55544244 - (MISC) https://kb.filewave.com/pages/viewpage.action?pageId=55544244 - Release Notes, Third Party Advisory
References (MISC) https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/ - (MISC) https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/ - Exploit, Third Party Advisory

25 Jul 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-25 21:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-34906

Mitre link : CVE-2022-34906

CVE.ORG link : CVE-2022-34906


JSON object : View

Products Affected

filewave

  • filewave
CWE
CWE-798

Use of Hard-coded Credentials