ID

VAR-202403-2944


TITLE

There is a command execution vulnerability (CNVD-2022-53245) in the operation and maintenance audit system of Beijing COSCO Kirin Technology Co., Ltd.

Trust: 0.6

sources: CNVD: CNVD-2022-53245

DESCRIPTION

Beijing COSCO Kirin Technology Co., Ltd. is a software development company focusing on research and development. The company's main products are COSCO Kirin bastion host, Kirin SSL VPN, Kirin dynamic password system, Kirin cloud desktop, etc. COSCO Kirin bastion machines mainly operate in cloud markets such as Tencent Cloud, Alibaba Cloud, Huawei Cloud, and Inspur Cloud. There is a command execution vulnerability in the operation and maintenance audit system of Beijing COSCO Kirin Technology Co., Ltd. An attacker can use this vulnerability to gain control of the server.

Trust: 0.6

sources: CNVD: CNVD-2022-53245

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-53245

AFFECTED PRODUCTS

vendor:cosco kirinmodel:operation and maintenance audit systemscope:eqversion:1.7-2021-0718

Trust: 0.6

sources: CNVD: CNVD-2022-53245

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2022-53245
value: HIGH

Trust: 0.6

CNVD: CNVD-2022-53245
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:H/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2022-53245

PATCH

title:Patch for There is a command execution vulnerability (CNVD-2022-53245) in the operation and maintenance audit system of Beijing COSCO Kirin Technology Co., Ltd.url:https://www.cnvd.org.cn/patchinfo/show/532976

Trust: 0.6

sources: CNVD: CNVD-2022-53245

EXTERNAL IDS

db:CNVDid:CNVD-2022-53245

Trust: 0.6

sources: CNVD: CNVD-2022-53245

SOURCES

db:CNVDid:CNVD-2022-53245

LAST UPDATE DATE

2024-03-29T22:39:26.466000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-53245date:2024-03-15T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-53245date:2024-03-15T00:00:00