« Volver al listado

CVE-2022-25153

Estado: ModificadaAlta (7.8)—

The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-25153",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "csirt@divd.nl",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "csirt@divd.nl",
      "affectedData": [
        {
          "vendor": "ITarian",
          "product": "Endpoint Manager Communication Client for Windows",
          "versions": [
            {
              "status": "affected",
              "version": "any version",
              "lessThan": "6.43.41148.21120",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-06-09T17:15:08.903",
  "references": [
    {
      "url": "https://csirt.divd.nl/CVE-2022-25153",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "csirt@divd.nl"
    },
    {
      "url": "https://csirt.divd.nl/DIVD-2021-00037",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "csirt@divd.nl"
    },
    {
      "url": "https://csirt.divd.nl/CVE-2022-25153",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://csirt.divd.nl/DIVD-2021-00037",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "csirt@divd.nl",
      "description": [
        {
          "lang": "en",
          "value": "CWE-275"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup."
    },
    {
      "lang": "es",
      "value": "El cliente de comunicación de ITarian Endpoint Manage, versiones anteriores a 6.43.41148.21120, es compilado usando una configuración no segura de OpenSSL. Debido a esta configuración, un actor malicioso con acceso de bajos privilegios a un sistema puede escalar sus privilegios a SYSTEM abusando de una búsqueda no segura de openssl.conf"
    }
  ],
  "lastModified": "2026-06-17T04:33:06.217",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:itarian:endpoint_manager_communication_client:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "293D7861-2A0A-48DE-9116-DEAE177143F6",
              "versionEndExcluding": "7.0.42012.22030"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "csirt@divd.nl"
}