HIGH
Hima: Unquoted path vulnerabilities in HIMA PC based Software
Published Jan 16, 2023
7.8
HIGHCVSS 3.1
EPSS 0.21%
Description
In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to gain privileges via a malicious .exe file and gain full access to the system.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<=3.56.4
- Version
-
- Version 1.0.0StatusaffectedConstraints<=5.6.1210
- Version
-
- Version 1.0.0StatusaffectedConstraints<=5.6.1210
- Version
-
- Version 1.0.0StatusaffectedConstraints<=1.32.550
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HIMA | Hopcs | unaffected |
| ||||||
| HIMA | X-Opc A+e | unaffected |
| ||||||
| HIMA | X-Opc da | unaffected |
| ||||||
| HIMA | X-OTS | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://cert.vde.com/en/advisories/VDE-2022-059/ MitigationThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://cert.vde.com/en/advisories/VDE-2022-059/ | MitigationThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERTVDE
Published Jan 16, 2023
Updated Apr 3, 2025
Reserved Dec 1, 2022
Link CVE-2022-4258
CISA Vulnrichment
Updated Apr 3, 2025