ZeroHour

CVE-2022-35629

CVSS 3.1
5.4 medium
EPSS
<1%p37
Published
()
Modified
Description

Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved in Velociraptor 0.6.5-2.

Vendors
rapid7
Products
velociraptor
Weakness
CWE-287, CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.