CVE-2022-32962

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
20/07/2022
Last modified:
02/08/2022

Description

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30306:*:*:*:*:linux:*:*
cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30404:*:*:*:*:macos:*:*
cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.1.0.00002:*:*:*:*:windows:*:*


References to Advisories, Solutions, and Tools