ID

VAR-202302-1442


CVE

CVE-2022-41614


TITLE

Intel's  Android  for  on event series  Vulnerability regarding insufficient protection of authentication information in

Trust: 0.8

sources: JVNDB: JVNDB-2022-020302

DESCRIPTION

Insufficiently protected credentials in the Intel(R) ON Event Series Android application before version 2.0 may allow an authenticated user to potentially enable information disclosure via local access. Intel's Android for on event series There are vulnerabilities in inadequate protection of credentials.Information may be obtained

Trust: 1.8

sources: NVD: CVE-2022-41614 // JVNDB: JVNDB-2022-020302 // VULHUB: VHN-437862 // VULMON: CVE-2022-41614

AFFECTED PRODUCTS

vendor:intelmodel:on event seriesscope:ltversion:2.0

Trust: 1.0

vendor:インテルmodel:on event seriesscope: - version: -

Trust: 0.8

vendor:インテルmodel:on event seriesscope:eqversion:2.0

Trust: 0.8

vendor:インテルmodel:on event seriesscope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-020302 // NVD: CVE-2022-41614

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-41614
value: MEDIUM

Trust: 1.0

secure@intel.com: CVE-2022-41614
value: MEDIUM

Trust: 1.0

NVD: CVE-2022-41614
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202302-1464
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2022-41614
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 2.0

NVD: CVE-2022-41614
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-020302 // CNNVD: CNNVD-202302-1464 // NVD: CVE-2022-41614 // NVD: CVE-2022-41614

PROBLEMTYPE DATA

problemtype:CWE-522

Trust: 1.1

problemtype:Inadequate protection of credentials (CWE-522) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-437862 // JVNDB: JVNDB-2022-020302 // NVD: CVE-2022-41614

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202302-1464

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202302-1464

PATCH

title:Intel ON Event Series Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=228037

Trust: 0.6

sources: CNNVD: CNNVD-202302-1464

EXTERNAL IDS

db:NVDid:CVE-2022-41614

Trust: 3.4

db:JVNid:JVNVU91223897

Trust: 0.8

db:JVNDBid:JVNDB-2022-020302

Trust: 0.8

db:CNNVDid:CNNVD-202302-1464

Trust: 0.6

db:VULHUBid:VHN-437862

Trust: 0.1

db:VULMONid:CVE-2022-41614

Trust: 0.1

sources: VULHUB: VHN-437862 // VULMON: CVE-2022-41614 // JVNDB: JVNDB-2022-020302 // CNNVD: CNNVD-202302-1464 // NVD: CVE-2022-41614

REFERENCES

url:http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00776.html

Trust: 2.6

url:https://jvn.jp/vu/jvnvu91223897/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2022-41614

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-41614/

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-437862 // VULMON: CVE-2022-41614 // JVNDB: JVNDB-2022-020302 // CNNVD: CNNVD-202302-1464 // NVD: CVE-2022-41614

SOURCES

db:VULHUBid:VHN-437862
db:VULMONid:CVE-2022-41614
db:JVNDBid:JVNDB-2022-020302
db:CNNVDid:CNNVD-202302-1464
db:NVDid:CVE-2022-41614

LAST UPDATE DATE

2024-08-14T12:10:24.315000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-437862date:2023-03-07T00:00:00
db:VULMONid:CVE-2022-41614date:2023-02-17T00:00:00
db:JVNDBid:JVNDB-2022-020302date:2023-11-01T06:55:00
db:CNNVDid:CNNVD-202302-1464date:2023-03-08T00:00:00
db:NVDid:CVE-2022-41614date:2023-03-07T22:03:40.953

SOURCES RELEASE DATE

db:VULHUBid:VHN-437862date:2023-02-16T00:00:00
db:VULMONid:CVE-2022-41614date:2023-02-16T00:00:00
db:JVNDBid:JVNDB-2022-020302date:2023-11-01T00:00:00
db:CNNVDid:CNNVD-202302-1464date:2023-02-16T00:00:00
db:NVDid:CVE-2022-41614date:2023-02-16T21:15:13.947