CVE Vulnerabilities

CVE-2022-30623

Authentication Bypass Using an Alternate Path or Channel

Published: Jul 18, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The server checks the users cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
P5e_gnss_firmware Chcnav 4.1 (including) 4.1 (including)
P5e_gnss_firmware Chcnav 4.2 (including) 4.2 (including)

Potential Mitigations

References