Fiche vulnérabilité
CVE-2022-34906 : faille élevée filewave filewave (CVSS 7.5)
Description
A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 25 juil. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- filewave filewave