CVE-2022-34907
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
25/07/2022
Last modified:
08/08/2023
Description
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:* | 14.6.3 (excluding) | |
| cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:* | 14.7.0 (including) | 14.7.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



