← All CVEs

CVE-2022-34906

high · 7.5

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.

7.5
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2022-07-25
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-798

Affected products

VendorProductAffected versions
filewavefilewave< 14.6.3
filewavefilewave>= 14.7.0, < 14.7.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-34906