// For flags

CVE-2022-47634

 

Severity Score

8.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LINK-2867.

M-Link Archive Server en Isode M-Link R16.2v1 a R17.0 anterior a R17.0v24 permite a usuarios no administrativos acceder y manipular datos de archivo a través de ciertos endpoints HTTP, también conocidos como LINK-2867.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-12-20 CVE Reserved
  • 2023-01-01 CVE Published
  • 2024-07-24 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Isode
Search vendor "Isode"
M-link
Search vendor "Isode" for product "M-link"
>= r16.2v1 < r17.0v24
Search vendor "Isode" for product "M-link" and version " >= r16.2v1 < r17.0v24"
-
Affected