« Volver al listado

CVE-2022-21170

Estado: ModificadaBaja (3.7)—

Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILTER Browser & Cloud MultiAgent for Windows Ver.4.93R04 and earlier, and D-SPA (Ver.3 / Ver.4) using i-FILTER allows a remote unauthenticated attacker to conduct a man-in-the-middle attack and eavesdrop on an encrypted communication.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-21170",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Digital Arts Inc.",
          "product": "i-FILTER, i-FILTER Browser & Cloud MultiAgent for Windows, and D-SPA using i-FILTER",
          "versions": [
            {
              "status": "affected",
              "version": "i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILTER Browser & Cloud MultiAgent for Windows Ver.4.93R04 and earlier, and D-SPA (Ver.3 / Ver.4) using i-FILTER"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-03-10T17:45:10.083",
  "references": [
    {
      "url": "https://download.daj.co.jp/user/dspa/V3/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://download.daj.co.jp/user/dspa/V4/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://download.daj.co.jp/user/ifb/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://download.daj.co.jp/user/ifilter/V10/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://download.daj.co.jp/user/ifilter/V9/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN33214411/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://download.daj.co.jp/user/dspa/V3/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://download.daj.co.jp/user/dspa/V4/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://download.daj.co.jp/user/ifb/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://download.daj.co.jp/user/ifilter/V10/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://download.daj.co.jp/user/ifilter/V9/",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN33214411/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILTER Browser & Cloud MultiAgent for Windows Ver.4.93R04 and earlier, and D-SPA (Ver.3 / Ver.4) using i-FILTER allows a remote unauthenticated attacker to conduct a man-in-the-middle attack and eavesdrop on an encrypted communication."
    },
    {
      "lang": "es",
      "value": "Una comprobación inapropiada de la revocación de certificados en i-FILTER Versiones 10.45R01 y anteriores, i-FILTER Versiones 9.50R10 y anteriores, i-FILTER Browser & Cloud MultiAgent para Windows Versiones 4.93R04 y anteriores, y D-SPA (Versión 3 / Versión 4) usando i-FILTER permite a un atacante remoto no autenticado realizar un ataque de tipo man-in-the-middle y espiar una comunicación cifrada"
    }
  ],
  "lastModified": "2026-06-17T04:25:40.313",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:daj:i-filter_browser_\\&_cloud_multiagent:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A067113-D8E7-44A5-8B94-C60259A003DD",
              "versionEndIncluding": "4.93r04"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:daj:i-filter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8322913-9EC0-4A2C-BB6E-CED5BA681B6F",
              "versionEndIncluding": "9.50r10"
            },
            {
              "criteria": "cpe:2.3:a:daj:i-filter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEEBABB4-18EA-47A8-A421-B6733EB2C9AD",
              "versionEndIncluding": "10.45r01",
              "versionStartIncluding": "10.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:daj:dspa-15000_m5:3:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9D48721B-0841-49AB-BD04-2C48F4C23EEC"
            },
            {
              "criteria": "cpe:2.3:h:daj:dspa-15000_m5:4:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A5B5073D-2359-4A37-B203-D45799BA9045"
            },
            {
              "criteria": "cpe:2.3:h:daj:dspa-2000_m4:4:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "950E990E-8809-4E06-BCD3-9AE4DE613B01"
            },
            {
              "criteria": "cpe:2.3:h:daj:dspa-4000_m4:4:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2D521EF9-C517-4114-8AA8-0DD78BE19476"
            },
            {
              "criteria": "cpe:2.3:h:daj:dspa-7000_m5:3:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "45FC586C-85E6-469D-8A4E-C145E60B3109"
            },
            {
              "criteria": "cpe:2.3:h:daj:dspa-7000_m5:4:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "399E9A87-DF61-4B0C-8134-3912E8161904"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}