CVE-2022-38130
52Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actepss 53%
de la publicación al arma
Publicada en NVD10 ago
VulnCheck+465d
probabilidad de explotación
53%top 1% de las CVE
explotación observada
síVulnCheck
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored.
Productos afectados
n/a · Keysight Technologies Sensor Management Server