CVE-2022-1289

MEDIUMCVSS 6.5/10EPSS 1.10%

Last modified

CVE-2022-1289 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. EPSS estimates a 1.10% chance of exploitation in the next 30 days.

Description

A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to an incomplete fix of CVE-2022-1211. It is possible to initiate the attack remotely but it requires user interaction. The issue got fixed with the patch 0eb02422d5161767e9983bdaa5c429762d3477ce.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Probability
1.10%

61.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
TildearrowFurnaceAll versions
TildearrowFurnace0.2
TildearrowFurnace0.2.1
TildearrowFurnace0.2.2
TildearrowFurnace0.3
TildearrowFurnace0.3.1
TildearrowFurnace0.4
TildearrowFurnace0.4.1
TildearrowFurnace0.4.2
TildearrowFurnace0.4.3
TildearrowFurnace0.4.4
TildearrowFurnace0.4.5
TildearrowFurnace0.4.6
TildearrowFurnace0.4.7
TildearrowFurnace0.5
TildearrowFurnace0.5.1
TildearrowFurnace0.5.2
TildearrowFurnace0.5.3
TildearrowFurnace0.5.4
TildearrowFurnace0.5.5
TildearrowFurnace0.5.6
TildearrowFurnace0.5.7
TildearrowFurnace0.5.8
TildearrowFurnace0.6Pre0
TildearrowFurnacedev5
TildearrowFurnacedev6
TildearrowFurnacedev7
TildearrowFurnacedev8
TildearrowFurnacedev9
TildearrowFurnacedev10
TildearrowFurnacedev62
TildearrowFurnacedev63
TildearrowFurnacedev64
TildearrowFurnacedev65
TildearrowFurnacedev66
TildearrowFurnacedev67
TildearrowFurnacedev68
TildearrowFurnacedev69
TildearrowFurnacedev70
TildearrowFurnacedev71
TildearrowFurnacedev72
TildearrowFurnacedev73
TildearrowFurnacedev75
TildearrowFurnacedev76
TildearrowFurnacedev77
TildearrowFurnacedev78
TildearrowFurnacedev79
TildearrowFurnacedev80

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-1289?
A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to an incomplete fix of CVE-2022-1211. It is possible to initiate the attack remotely but it requires user interaction. The issue got fixed with the patch 0eb02422d5161767e9983bdaa5c429762d3477ce.
How severe is CVE-2022-1289?
CVE-2022-1289 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 1.10% probability of exploitation in the next 30 days.
How do I fix CVE-2022-1289?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-1289?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST