CVE-2022-34907

An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*
cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*

History

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-287 CWE-798

02 Aug 2022, 17:32

Type Values Removed Values Added
CPE cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-287
References (MISC) https://kb.filewave.com/pages/viewpage.action?pageId=55544244 - (MISC) https://kb.filewave.com/pages/viewpage.action?pageId=55544244 - Release Notes, Third Party Advisory
References (MISC) https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/ - (MISC) https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/ - Exploit, Third Party Advisory

25 Jul 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-25 21:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-34907

Mitre link : CVE-2022-34907

CVE.ORG link : CVE-2022-34907


JSON object : View

Products Affected

filewave

  • filewave
CWE
CWE-798

Use of Hard-coded Credentials