CVE-2022-3884
Last modified
CVE-2022-3884 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID Agent component) allows local users to read and write specific files.This issue affects Hitachi Ops Center Analyzer: from 10.9.0-00 before 10.9.0-01. . EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID Agent component) allows local users to read and write specific files.This issue affects Hitachi Ops Center Analyzer: from 10.9.0-00 before 10.9.0-01.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Ops Center Analyzer | >= 10.9.0-00, < 10.9.1-00 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3884?
How severe is CVE-2022-3884?
How do I fix CVE-2022-3884?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-38829Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow …9.8
- CVE-2022-3883The Block Bad Bots and Stop Bad Bots Crawlers and Spiders an…6.5
- CVE-2022-38830Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow …9.8
- CVE-2022-38831Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow …9.8
- CVE-2022-38832School Activity Updates with SMS Notification v1.0 is vulner…7.2
- CVE-2022-38833School Activity Updates with SMS Notification v1.0 is vulner…7.2
- CVE-2022-38840cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulner…7.5
- CVE-2022-38841Linksys AX3200 1.1.00 is vulnerable to OS command injection …8.8
- CVE-2022-38843EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upl…8.8
- CVE-2022-38844CSV Injection in Create Contacts in EspoCRM 7.1.8 allows rem…8
- CVE-2022-38845Cross Site Scripting in Import feature in EspoCRM 7.1.8 allo…6.1
- CVE-2022-38846EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag a…5.9
Are you affected by CVE-2022-3884?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
