CVE-2022-38130

CRITICALCVSS 9.8/10EPSS 53.39%

Last modified

CVE-2022-38130 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. EPSS estimates a 53.39% chance of exploitation in the next 30 days.

Description

The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
53.39%

98.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
KeysightSensor Management Server2.4.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-38130?
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored.
How severe is CVE-2022-38130?
CVE-2022-38130 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 53.39% probability of exploitation in the next 30 days.
How do I fix CVE-2022-38130?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-38130?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST