« Volver al listado

CVE-2022-30622

Estado: ModificadaAlta (7.3)—

Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be possible to enter the system. Path access: http://api/sys_username_passwd.cmd - The server loads the request clearly by default. Disclosure of hard-coded credit information within the JS code sent to the customer within the Login.js file is a strong user (which is not documented) and also the password, which allow for super-user access. Username: chcadmin, Password: chcpassword.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-30622",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@cyber.gov.il",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "cna@cyber.gov.il",
      "affectedData": [
        {
          "vendor": "Chcnav",
          "product": "Chcnav - P5E GNSS",
          "versions": [
            {
              "status": "affected",
              "version": "4.2",
              "lessThan": "4.1*",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-07-17T21:15:08.803",
  "references": [
    {
      "url": "https://www.gov.il/en/Departments/faq/cve_advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cna@cyber.gov.il"
    },
    {
      "url": "https://www.gov.il/en/Departments/faq/cve_advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be possible to enter the system. Path access: http://api/sys_username_passwd.cmd - The server loads the request clearly by default. Disclosure of hard-coded credit information within the JS code sent to the customer within the Login.js file is a strong user (which is not documented) and also the password, which allow for super-user access. Username: chcadmin, Password: chcpassword."
    },
    {
      "lang": "es",
      "value": "Una revelación de información: el sistema permite visualizar los nombres de usuario y las contraseñas sin permisos, por lo que será posible entrar en el sistema. Acceso a la ruta: http://api/sys_username_passwd.cmd - El servidor carga la petición de forma clara por defecto. La divulgación de la información de crédito embebida en el código JS que es enviado al cliente dentro del archivo Login.js es un usuario fuerte (que no está documentado) y también la contraseña, que permiten el acceso de super usuario. Nombre de usuario: chcadmin, Contraseña: chcpassword"
    }
  ],
  "lastModified": "2026-06-17T04:43:57.680",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:chcnav:p5e_gnss_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D517250C-921A-494E-9B38-6154732AA2E5",
              "versionEndIncluding": "4.1"
            },
            {
              "criteria": "cpe:2.3:o:chcnav:p5e_gnss_firmware:4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B26293DB-77D5-4417-B72C-6EEDFE6151D5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:chcnav:p5e_gnss:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "56783F0F-85AA-4B6F-BC24-3F7659A86567"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cna@cyber.gov.il"
}