CVE-2022-22703
MEDIUMCVSS 5.5/10EPSS 0.24%
Last modified
CVE-2022-22703 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stormshield | Network Security | >= 2.0.0, < 2.1.1 |
| Stormshield | Network Security | >= 3.0.0, < 3.0.2 |
References
- https://advisories.stormshield.eu/2022-001Vendor Advisory
- https://advisories.stormshield.eu/2022-001Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22703?
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
How severe is CVE-2022-22703?
CVE-2022-22703 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2022-22703?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22690Within the Umbraco CMS, a configuration element named "Umbra…7.5
- CVE-2022-22691The password reset component deployed within Umbraco uses th…7.4
- CVE-2022-2270An issue has been discovered in GitLab affecting all version…5.3
- CVE-2022-22700CyberArk Identity versions up to and including 22.1 in the '…5.3
- CVE-2022-22701PartKeepr versions up to v1.4.0, loads attachments using a U…6.5
- CVE-2022-22702PartKeepr versions up to v1.4.0, in the functionality to upl…4.3
- CVE-2022-22704The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux s…9.8
- CVE-2022-22706Arm Mali GPU Kernel Driver allows a non-privileged user to a…7.8
- CVE-2022-22707In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwar…5.9
- CVE-2022-22709VP9 Video Extensions Remote Code Execution Vulnerability7.8
- CVE-2022-2271The WP Database Backup WordPress plugin before 5.9 does not …4.8
- CVE-2022-22710Windows Common Log File System Driver Denial of Service Vuln…5.5
Are you affected by CVE-2022-22703?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
