« Volver al listado

CVE-2022-36174

Estado: ModificadaAlta (8.1)—

FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-36174",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-12T21:15:10.763",
  "references": [
    {
      "url": "https://community.freshworks.com/product-updates/freshservice-release-notes-april-2022-23982#Security+updates:+Discovery+Probe+and+Discovery+Agent",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://public-exposure.inform.social/post/integrity-checking/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://community.freshworks.com/product-updates/freshservice-release-notes-april-2022-23982#Security+updates:+Discovery+Probe+and+Discovery+Agent",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://public-exposure.inform.social/post/integrity-checking/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-354"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service."
    },
    {
      "lang": "es",
      "value": "FreshService Windows Agent versiones anteriores a 2.11.0 y FreshService macOS Agent versiones anteriores a 4.2.0 y FreshService Linux Agent versiones anteriores a 3.3.0. son vulnerables a una comprobación de integridad rota por medio del cliente FreshAgent y el servicio de actualización programada"
    }
  ],
  "lastModified": "2026-06-17T04:53:02.053",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:freshworks:freshservice_agent:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D07617AE-F2AA-4350-B72C-7722B044BE11",
              "versionEndExcluding": "2.11.0"
            },
            {
              "criteria": "cpe:2.3:a:freshworks:freshservice_agent:*:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "582E21BB-A20A-4BF9-95EF-1F9ADBE4D929",
              "versionEndExcluding": "3.3.0"
            },
            {
              "criteria": "cpe:2.3:a:freshworks:freshservice_agent:*:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFB6F154-38ED-4CAA-BDE6-9B8EBCEA051B",
              "versionEndExcluding": "4.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}