CVE-2022-31887
Last modified
CVE-2022-31887 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.. EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Marvalglobal | Marval Msm | 14.19.0.12476 |
References
- https://cyber-guy.gitbook.io/cyber-guy/pocs/marval-msm/0-click-account-takeoverExploit, Third Party Advisory
- https://drive.google.com/drive/folders/12nb9KvckzhUNv4RtjlaeZi8QeFqwvkMX?usp=sharingBroken Link, Third Party Advisory
- https://marvalglobal.com/Product
- https://cyber-guy.gitbook.io/cyber-guy/pocs/marval-msm/0-click-account-takeoverExploit, Third Party Advisory
- https://drive.google.com/drive/folders/12nb9KvckzhUNv4RtjlaeZi8QeFqwvkMX?usp=sharingBroken Link, Third Party Advisory
- https://marvalglobal.com/Product
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31887?
How severe is CVE-2022-31887?
How do I fix CVE-2022-31887?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31879Online Fire Reporting System 1.0 is vulnerable to SQL Inject…8.8
- CVE-2022-3188Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 conta…5.3
- CVE-2022-31883Marval MSM v14.19.0.12476 is has an Insecure Direct Object R…8.8
- CVE-2022-31884Marval MSM v14.19.0.12476 has an Improper Access Control vul…6.5
- CVE-2022-31885Marval MSM v14.19.0.12476 is vulnerable to OS Command Inject…9.8
- CVE-2022-31886Marval MSM v14.19.0.12476 is vulnerable to Cross Site Reques…6.5
- CVE-2022-31888Session Fixation vulnerability in in function login in class…8.8
- CVE-2022-31889Cross Site Scripting (XSS) vulnerability in audit/templates/…6.1
- CVE-2022-3189Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 conta…5.3
- CVE-2022-31890SQL Injection vulnerability in audit/class.audit.php in osTi…9.8
- CVE-2022-31897SourceCodester Zoo Management System 1.0 is vulnerable to Cr…6.1
- CVE-2022-31898gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214…6.8
Are you affected by CVE-2022-31887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
