CVE-2022-0183
Status: ModifiedMedium (4.6)—
Missing encryption of sensitive data vulnerability in 'MIRUPASS' PW10 firmware all versions and 'MIRUPASS' PW20 firmware all versions allows an attacker who can physically access the device to obtain the stored passwords.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 4.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.11%
- Percentile among all scored CVEs: 1
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-311
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-0183",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.6,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "KING JIM CO.,LTD.",
"product": "MIRUPASS",
"versions": [
{
"status": "affected",
"version": "'MIRUPASS' PW10 firmware all versions and 'MIRUPASS' PW20 firmware all versions"
}
]
}
]
}
],
"published": "2022-01-17T10:15:08.200",
"references": [
{
"url": "https://jvn.jp/en/jp/JVN19826500/index.html",
"tags": [
"Third Party Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.kingjim.co.jp/download/security/#mirupass",
"tags": [
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/jp/JVN19826500/index.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.kingjim.co.jp/download/security/#mirupass",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-311"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Missing encryption of sensitive data vulnerability in 'MIRUPASS' PW10 firmware all versions and 'MIRUPASS' PW20 firmware all versions allows an attacker who can physically access the device to obtain the stored passwords."
},
{
"lang": "es",
"value": "Una vulnerabilidad de falta de cifrado de datos confidenciales en el firmware de \"MIRUPASS\" PW10 todas las versiones y en el firmware de \"MIRUPASS\" PW20 todas las versiones permite a un atacante que pueda acceder físicamente al dispositivo obtener las contraseñas almacenadas"
}
],
"lastModified": "2026-06-17T04:20:06.720",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:kingjim:mirupass_pw10_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9FB74D3-B6AA-415E-9864-AEC01357401F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:kingjim:mirupass_pw10:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A965B937-4E1D-40F6-947E-816BA0B48EE8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:kingjim:mirupass_pw20_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "22A8DD2F-2606-4AD5-BE79-088B3A50D30A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:kingjim:mirupass_pw20:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "00914630-3A9A-472D-8FA0-80FB046F7384"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}