« Volver al listado

CVE-2022-35222

Estado: ModificadaMedia (6.8)—

HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter length validation. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-35222",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "HINET",
          "product": "HiCOS Citizen verification component - Stack Buffer Overflow",
          "versions": [
            {
              "status": "affected",
              "version": "libHicos_p11v1.so CHT PKCS#11 3.0.3.30306"
            }
          ],
          "platforms": [
            "Linux"
          ]
        },
        {
          "vendor": "HINET",
          "product": "HiCOS Citizen verification component - Stack Buffer Overflow",
          "versions": [
            {
              "status": "affected",
              "version": "HiCOSPKCS11.dll CHT PKCS#11 3.1.0.00002"
            }
          ],
          "platforms": [
            "Windows"
          ]
        },
        {
          "vendor": "HINET",
          "product": "HiCOS Citizen verification component - Stack Buffer Overflow",
          "versions": [
            {
              "status": "affected",
              "version": "libHicos_p11v1.dylib CHT PKCS#11 3.0.3.30404"
            }
          ],
          "platforms": [
            "macOS"
          ]
        }
      ]
    }
  ],
  "published": "2022-08-02T16:15:10.820",
  "references": [
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-6363-f5ec2-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-6363-f5ec2-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter length validation. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service."
    },
    {
      "lang": "es",
      "value": "El componente de verificación HiCOS Citizen presenta una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria debido a la insuficiente comprobación de la longitud de los parámetros. Un atacante físico no autenticado puede explotar esta vulnerabilidad para ejecutar código arbitrario, manipular el comando del sistema o interrumpir el servicio"
    }
  ],
  "lastModified": "2026-06-17T04:51:35.200",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30306:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C3A74A9-114E-4326-B71C-83FFA3580E63"
            },
            {
              "criteria": "cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30404:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7800A8CE-C635-4E00-8BEA-E3E4D4EC9378"
            },
            {
              "criteria": "cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.1.0.00002:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48F1D51B-28F3-4952-BB19-9BCA637DF577"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "twcert@cert.org.tw"
}