Changingtec
Changingtec Rava Certificate Validation System: vulnerabilidades y CVE
Changingtec Rava Certificate Validation System tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-39058 | Alta (7.5) | 1.9% | — | 18 oct 2022 | RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files. |
| CVE-2022-39057 | Alta (7.2) | 0.76% | — | 18 oct 2022 | RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perform arbitrary system… |
| CVE-2022-39056 | Crítica (9.8) | 0.84% | — | 18 oct 2022 | RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database. |
| CVE-2022-39055 | Media (5.3) | 0.46% | — | 18 oct 2022 | RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response. |