Description
RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perform arbitrary system command and disrupt service.
No analysis available yet.
Remediation
Vendor Solution
Contact tech support from Changing Information Technology Inc.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-41603 | RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perform arbitrary system command and disrupt service. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-6618-11fd8-1.html |
|
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 08 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-05-08T19:44:04.416Z
Reserved: 2022-08-31T00:00:00.000Z
Link: CVE-2022-39057
Updated: 2024-08-03T11:10:32.465Z
Status : Modified
Published: 2022-10-18T06:15:09.197
Modified: 2024-11-21T07:17:28.227
Link: CVE-2022-39057
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD