CVE-2022-34906

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*
cpe:2.3:a:filewave:filewave:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-07-25 21:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-34906

Mitre link : CVE-2022-34906

CVE.ORG link : CVE-2022-34906


JSON object : View

Products Affected

filewave

  • filewave
CWE
CWE-798

Use of Hard-coded Credentials