ZeroHour

CVE-2022-34906

PoC
CVSS 3.1
7.5 high
EPSS
11%p96
Published
()
Modified
Description

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.

Vendors
filewave
Products
filewave
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news