Vulnerability Details CVE-2022-3229
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.885
EPSS Ranking 99.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-3229
-
cpe:2.3:a:unifiedremote:unified_remote:-
-
cpe:2.3:a:unifiedremote:unified_remote:3.11.0.2483
-
cpe:2.3:o:microsoft:windows:-