CVE-2022-28795
Last modified
CVE-2022-28795 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this information via JavaScript. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this information via JavaScript. The issue was fixed with the browser extensions version 2.18.5 for Chrome, MS Edge, Opera, Firefox, and Safari.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avira | Password Manager | 2.18.4 |
| Avira | Password Manager | 2.18.4.3847 |
| Avira | Password Manager | 2.18.4.3868 |
| Avira | Password Manager | 2.18.4.38471 |
References
- https://support.norton.com/sp/static/external/tools/security-advisories.htmlThird Party Advisory
- https://support.norton.com/sp/static/external/tools/security-advisories.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-28795?
How severe is CVE-2022-28795?
How do I fix CVE-2022-28795?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-2879Reader.Read does not set a limit on the maximum size of file…7.5
- CVE-2022-28790Improper authentication in Link to Windows Service prior to …3.3
- CVE-2022-28791Improper input validation vulnerability in InstallAgent in G…5.5
- CVE-2022-28792DLL hijacking vulnerability in Gear IconX PC Manager prior t…7.8
- CVE-2022-28793Given the TEE is compromised and controlled by the attacker,…4.4
- CVE-2022-28794Sensitive information exposure in low-battery dumpstate log …3.3
- CVE-2022-28796jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Li…7
- CVE-2022-28799The TikTok application before 23.7.3 for Android allows acco…8.8
- CVE-2022-2880Requests forwarded by ReverseProxy include the raw query par…7.5
- CVE-2022-28802Code by Zapier before 2022-08-17 allowed intra-account privi…9.9
- CVE-2022-28803In SilverStripe Framework through 2022-04-07, Stored XSS can…5.4
- CVE-2022-28805singlevar in lparser.c in Lua from (including) 5.4.0 up to (…9.1
Are you affected by CVE-2022-28795?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
