« Volver al listado

CVE-2022-33861

Estado: AplazadaMedia (5.1)—

IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a way that causes it to accept invalid data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-33861",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-33861",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-25T13:57:15.676713Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "CybersecurityCOE@eaton.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.1,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "CybersecurityCOE@eaton.com",
      "affectedData": [
        {
          "vendor": "Eaton",
          "product": "Intelligent Power Protector",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.71",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:eaton:intelligent_power_protector:*:*:*:*:*:*:*:*"
          ],
          "vendor": "eaton",
          "product": "intelligent_power_protector",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.71",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-11-25T09:15:05.277",
  "references": [
    {
      "url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/ETN-VA-2022-1011.pdf",
      "source": "CybersecurityCOE@eaton.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "CybersecurityCOE@eaton.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-345"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a\nway that causes it to accept invalid data."
    },
    {
      "lang": "es",
      "value": "Las versiones del software IPP anteriores a la v1.71 no verifican suficientemente la autenticidad de los datos, lo que provoca que acepte datos no válidos."
    }
  ],
  "lastModified": "2026-06-17T04:49:23.300",
  "sourceIdentifier": "CybersecurityCOE@eaton.com"
}