CVE-2022-3929
Description
Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal messages.
This issue affects
* FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B, FOXMAN-UN R14A, FOXMAN-UN R11B, FOXMAN-UN R11A, FOXMAN-UN R10C, FOXMAN-UN R9C; * UNEM product: UNEM R15B, UNEM R15A, UNEM R14B, UNEM R14A, UNEM R11B, UNEM R11A, UNEM R10C, UNEM R9C.
List of CPEs: * cpe:2.3🅰️hitachienergy:foxman-un:R15B:*:*:*:*:*:*:*
* cpe:2.3🅰️hitachienergy:foxman-un:R15A:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:foxman-un:R14B:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:foxman-un:R14A:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:foxman-un:R11B:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:foxman-un:R11A:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:foxman-un:R10C:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:foxman-un:R9C:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:unem:R15B:*:*:*:*:*:*:*
* cpe:2.3🅰️hitachienergy:unem:R15A:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:unem:R14B:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:unem:R14A:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:unem:R11B:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:unem:R11A:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:unem:R10C:*:*:*:*:*:*:* * cpe:2.3🅰️hitachienergy:unem:R9C:*:*:*:*:*:*:*
- CVSS Version 3.1
CVE ID: CVE-2022-3929
Base Score: 8.3
Base Severity: HIGH
Vector String:CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Content on GitHub
doyensec | watchers:17
CVE-2022-39299_PoC_Generator
A Simple CVE-2022-39299 PoC exploit generator to bypass authentication in SAML SSO Integrations using vulnerable versions of passport-saml
Refrence: GitHub
Refrence: MITRE