OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate system data and disrupt service.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-6373-34d51-1.html | Third Party Advisory |
https://www.chtsecurity.com/news/48032532-b2de-401c-97a8-a2be5691988f | Third Party Advisory |
Configurations
Information
Published : 2022-08-04 03:15
Updated : 2022-10-25 19:49
NVD link : CVE-2022-32965
Mitre link : CVE-2022-32965
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
omicard_edm_project
- omicard_edm