PT-2022-3853 · Filewave · Filewave

Noam Moshe

·

Published

2022-07-25

·

Updated

2023-08-08

·

CVE-2022-34907

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FileWave versions prior to 14.6.3 FileWave versions 14.7.x prior to 14.7.2
Description The issue is related to errors during the authentication procedure in the FileWave platform, which is a cross-platform solution for mobile device management. Exploitation of this issue could allow a remote attacker to gain full access to the platform, potentially giving them the highest authority possible and full control over the system.
Recommendations For versions prior to 14.6.3, update to version 14.6.3 or later. For versions 14.7.x prior to 14.7.2, update to version 14.7.2 or later.

Exploit

Fix

Improper Authentication

XSS

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-04655
CVE-2022-34907

Affected Products

Filewave