ID

VAR-202212-0878


CVE

CVE-2022-43516


TITLE

Microsoft's  Windows Firewall  Vulnerabilities in products from multiple vendors such as

Trust: 0.8

sources: JVNDB: JVNDB-2022-023332

DESCRIPTION

A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI). Microsoft's Windows Firewall Unspecified vulnerabilities exist in products from multiple vendors.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2022-43516 // JVNDB: JVNDB-2022-023332 // VULHUB: VHN-440572

AFFECTED PRODUCTS

vendor:zabbixmodel:zabbixscope:eqversion:6.2.6

Trust: 1.0

vendor:microsoftmodel:windows firewallscope:eqversion: -

Trust: 1.0

vendor:zabbixmodel:zabbixscope:gteversion:6.2.0

Trust: 1.0

vendor:zabbixmodel:zabbixscope:gteversion:6.0.10

Trust: 1.0

vendor:zabbixmodel:zabbixscope:eqversion:6.0.12

Trust: 1.0

vendor:zabbixmodel:zabbixscope:ltversion:6.2.6

Trust: 1.0

vendor:zabbixmodel:zabbixscope:ltversion:6.0.12

Trust: 1.0

vendor:zabbixmodel:zabbixscope: - version: -

Trust: 0.8

vendor:マイクロソフトmodel:windows firewallscope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-023332 // NVD: CVE-2022-43516

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-43516
value: CRITICAL

Trust: 1.0

security@zabbix.com: CVE-2022-43516
value: MEDIUM

Trust: 1.0

NVD: CVE-2022-43516
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202212-2470
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2022-43516
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

security@zabbix.com: CVE-2022-43516
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 2.2
impactScore: 3.7
version: 3.1

Trust: 1.0

NVD: CVE-2022-43516
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-023332 // CNNVD: CNNVD-202212-2470 // NVD: CVE-2022-43516 // NVD: CVE-2022-43516

PROBLEMTYPE DATA

problemtype:CWE-16

Trust: 1.0

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:others (CWE-Other) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-023332 // NVD: CVE-2022-43516

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202212-2470

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202212-2470

PATCH

title:ZBX-22002 microsoft microsofturl:https://support.zabbix.com/browse/ZBX-22002

Trust: 0.8

title:Zabbix Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=216735

Trust: 0.6

sources: JVNDB: JVNDB-2022-023332 // CNNVD: CNNVD-202212-2470

EXTERNAL IDS

db:NVDid:CVE-2022-43516

Trust: 3.3

db:JVNDBid:JVNDB-2022-023332

Trust: 0.8

db:CNNVDid:CNNVD-202212-2470

Trust: 0.6

db:VULHUBid:VHN-440572

Trust: 0.1

sources: VULHUB: VHN-440572 // JVNDB: JVNDB-2022-023332 // CNNVD: CNNVD-202212-2470 // NVD: CVE-2022-43516

REFERENCES

url:https://support.zabbix.com/browse/zbx-22002

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-43516

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-43516/

Trust: 0.6

sources: VULHUB: VHN-440572 // JVNDB: JVNDB-2022-023332 // CNNVD: CNNVD-202212-2470 // NVD: CVE-2022-43516

SOURCES

db:VULHUBid:VHN-440572
db:JVNDBid:JVNDB-2022-023332
db:CNNVDid:CNNVD-202212-2470
db:NVDid:CVE-2022-43516

LAST UPDATE DATE

2024-08-14T14:49:28.626000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-440572date:2022-12-07T00:00:00
db:JVNDBid:JVNDB-2022-023332date:2023-11-28T05:33:00
db:CNNVDid:CNNVD-202212-2470date:2022-12-08T00:00:00
db:NVDid:CVE-2022-43516date:2022-12-07T17:23:42.017

SOURCES RELEASE DATE

db:VULHUBid:VHN-440572date:2022-12-05T00:00:00
db:JVNDBid:JVNDB-2022-023332date:2023-11-28T00:00:00
db:CNNVDid:CNNVD-202212-2470date:2022-12-05T00:00:00
db:NVDid:CVE-2022-43516date:2022-12-05T20:15:10.887