CVE-2022-28795
Estado: ModificadaMedia (6.5)—
A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this information via JavaScript. The issue was fixed with the browser extensions version 2.18.5 for Chrome, MS Edge, Opera, Firefox, and Safari.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.02%
- Percentil entre todas las CVEs puntuadas: 62
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-28795",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@nortonlifelock.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Avira Password Manager – Browser Extensions",
"versions": [
{
"status": "affected",
"version": "Avira Password Manager - extension for Chrome"
},
{
"status": "affected",
"version": "version 2.18.4.3868 Avira Password Manager - extension for MS Edge"
},
{
"status": "affected",
"version": "version 2.18.4.3847 Avira Password Manager - extension for Opera"
},
{
"status": "affected",
"version": "version 2.18.4.3847 Avira Password Manager - extension for Firefox"
},
{
"status": "affected",
"version": "version 2.18.4.38471 Avira Password Manager - extension for Safari"
},
{
"status": "affected",
"version": "version 2.18.4"
}
]
}
]
}
],
"published": "2022-04-12T17:15:10.940",
"references": [
{
"url": "https://support.norton.com/sp/static/external/tools/security-advisories.html",
"tags": [
"Third Party Advisory"
],
"source": "security@nortonlifelock.com"
},
{
"url": "https://support.norton.com/sp/static/external/tools/security-advisories.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this information via JavaScript. The issue was fixed with the browser extensions version 2.18.5 for Chrome, MS Edge, Opera, Firefox, and Safari."
},
{
"lang": "es",
"value": "Una vulnerabilidad en las extensiones de navegador de Avira Password Manager ofrecía una posible laguna en la que, si un usuario visitaba una página diseñada por un atacante, la vulnerabilidad detectada podía hacer que la extensión de Password Manager rellenara el campo de la contraseña automáticamente. Un atacante podría entonces acceder a esta información por medio de JavaScript. El problema ha sido corregido con la versión 2.18.5 de las extensiones del navegador para Chrome, MS Edge, Opera, Firefox y Safari"
}
],
"lastModified": "2026-06-17T04:39:05.530",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:avira:password_manager:2.18.4:*:*:*:*:safari:*:*",
"vulnerable": true,
"matchCriteriaId": "036D4EFA-5735-4CDC-927E-FDAFFC20AD58"
},
{
"criteria": "cpe:2.3:a:avira:password_manager:2.18.4.3847:*:*:*:*:edge:*:*",
"vulnerable": true,
"matchCriteriaId": "914F107C-0D3D-426A-803E-09F302F126FA"
},
{
"criteria": "cpe:2.3:a:avira:password_manager:2.18.4.3847:*:*:*:*:opera:*:*",
"vulnerable": true,
"matchCriteriaId": "704A646E-ACD2-46D4-B380-8DD8BEE11FD9"
},
{
"criteria": "cpe:2.3:a:avira:password_manager:2.18.4.3868:*:*:*:*:chrome:*:*",
"vulnerable": true,
"matchCriteriaId": "67A7F636-3C8C-48AD-965A-9F21A48FD607"
},
{
"criteria": "cpe:2.3:a:avira:password_manager:2.18.4.38471:*:*:*:*:firefox:*:*",
"vulnerable": true,
"matchCriteriaId": "0804892E-24B4-4F8C-9E8B-1FE1FD899A2C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@nortonlifelock.com"
}