CVE-2022-32958
Estado: ModificadaMedia (6.5)—
Un atacante remoto con privilegio de usuario general puede enviar un mensaje al grupo de chat de Teamplus Pro que exceda el límite de tamaño del mensaje, para terminar el proceso de chat de otros destinatarios de Teamplus Pro
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.98%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-770
- CWE-770
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-32958",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.7,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 4,
"exploitabilityScore": 3.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "twcert@cert.org.tw",
"affectedData": [
{
"vendor": "TEAMPLUS TECHNOLOGY INC.",
"product": "Teamplus Pro (Private cloud)",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "3.011.6.0.1"
}
],
"platforms": [
"Android"
]
},
{
"vendor": "TEAMPLUS TECHNOLOGY INC.",
"product": "Teamplus Pro (Private cloud)",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "3.011.6.0.1"
}
],
"platforms": [
"iOS"
]
}
]
}
],
"published": "2022-07-20T02:15:07.637",
"references": [
{
"url": "https://www.twcert.org.tw/tw/cp-132-6289-a5524-1.html",
"tags": [
"Third Party Advisory"
],
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-6289-a5524-1.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size limit, to terminate other recipients’ Teamplus Pro chat process."
},
{
"lang": "es",
"value": "Un atacante remoto con privilegio de usuario general puede enviar un mensaje al grupo de chat de Teamplus Pro que exceda el límite de tamaño del mensaje, para terminar el proceso de chat de otros destinatarios de Teamplus Pro"
}
],
"lastModified": "2026-06-17T04:48:17.940",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:teamplus:team\\+_pro:*:*:*:*:private_cloud:android:*:*",
"vulnerable": true,
"matchCriteriaId": "266BDB81-BE36-4A9D-BE19-9B96516B4E58",
"versionEndIncluding": "3.011.6.0.1"
},
{
"criteria": "cpe:2.3:a:teamplus:team\\+_pro:*:*:*:*:private_cloud:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "3E7BB0AB-B190-4997-9873-4E8C5FA60DED",
"versionEndIncluding": "3.011.6.0.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "twcert@cert.org.tw"
}