CVE-2022-3685
Last modified
CVE-2022-3685 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A vulnerability exists in the SDM600 software. The software operates at a privilege level that is higher than the minimum level required. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A vulnerability exists in the SDM600 software. The software operates at a privilege level that is higher than the minimum level required. An attacker who successfully exploits this vulnerability can escalate privileges. This issue affects: All SDM600 versions prior to version 1.3.0. List of CPEs: * cpe:2.3:a:hitachienergy:sdm600:1.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.9002.257:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.10002.257:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.11002.149:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.12002.222:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.13002.72:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.44:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.92:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.108:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.182:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.257:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.342:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.447:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.481:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.506:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.566:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.20000.3174:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.21000.291:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.21000.931:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.21000.105:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.23000.291:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.3.0.1339:*:*:*:*:*:*:*
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachienergy | Sdm600 | >= 1.0, < 1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3685?
How severe is CVE-2022-3685?
How do I fix CVE-2022-3685?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36844A heap-based overflow vulnerability in HWR::EngJudgeModel::C…7.8
- CVE-2022-36845A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO fu…7.8
- CVE-2022-36846A heap-based overflow vulnerability in ConstructDictionary f…7.8
- CVE-2022-36847Use after free vulnerability in mtp_send_signal function of …7.8
- CVE-2022-36848Improper Authorization vulnerability in setDualDARPolicyCmd …5.5
- CVE-2022-36849Use after free vulnerability in sdp_mm_set_process_sensitive…7.8
- CVE-2022-36850Path traversal vulnerability in CallBGProvider prior to SMR …4.7
- CVE-2022-36851Improper access control vulnerability in Samsung pass prior …4.6
- CVE-2022-36852Improper Authorization vulnerability in Video Editor prior t…3.3
- CVE-2022-36853Intent redirection in Photo Editor prior to SMR Sep-2022 Rel…7.5
- CVE-2022-36854Out of bound read in libapexjni.media.samsung.so prior to SM…5.5
- CVE-2022-36855A use after free vulnerability in iva_ctl driver prior to SM…7.8
Are you affected by CVE-2022-3685?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
