PT-2023-3970 · Unknown · Qvpn Device Client

Runzi Zhao

·

Published

2023-07-31

·

Updated

2024-12-24

·

CVE-2022-27595

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QVPN Device Client versions prior to 2.0.0.1310 QVPN Device Client versions prior to 2.0.0.1316
Description The issue is related to an insecure library loading vulnerability. If exploited, it could allow local attackers who have gained user access to execute unauthorized code or commands.
Recommendations For QVPN Device Client versions prior to 2.0.0.1310, update to version 2.0.0.1310 or later. For QVPN Device Client versions prior to 2.0.0.1316, update to version 2.0.0.1316 or later.

Fix

RCE

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2023-04266
CVE-2022-27595

Affected Products

Qvpn Device Client