// For flags

CVE-2022-4258

Hima: Unquoted path vulnerabilities in HIMA PC based Software

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to gain privileges via a malicious .exe file and gain full access to the system.

En varias versiones del software HIMA para PC, una vulnerabilidad de ruta de búsqueda de Windows sin comillas podría permitir a los usuarios locales obtener privilegios a través de un archivo .exe malicioso y obtener acceso completo al sistema.

In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to gain privileges via a malicious .exe file and gain full access to the system.

*Credits: This vulnerability has been found by a HIMA customer., Case handled by PSIRT@hima.com in cooperation with CERT@VDE
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-12-01 CVE Reserved
  • 2023-01-16 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-428: Unquoted Search Path or Element
CAPEC
  • CAPEC-38: Leveraging/Manipulating Configuration File Search Paths
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hima
Search vendor "Hima"
Hopcs
Search vendor "Hima" for product "Hopcs"
<= 3.56.4
Search vendor "Hima" for product "Hopcs" and version " <= 3.56.4"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Hima
Search vendor "Hima"
X-opc A\+e
Search vendor "Hima" for product "X-opc A\+e"
<= 5.6.1210
Search vendor "Hima" for product "X-opc A\+e" and version " <= 5.6.1210"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Hima
Search vendor "Hima"
X-opc Da
Search vendor "Hima" for product "X-opc Da"
<= 5.6.1210
Search vendor "Hima" for product "X-opc Da" and version " <= 5.6.1210"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Hima
Search vendor "Hima"
X-ots
Search vendor "Hima" for product "X-ots"
<= 1.32.550
Search vendor "Hima" for product "X-ots" and version " <= 1.32.550"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe