Vulnerability Details CVE-2022-32962
HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.3%
CVSS Severity
CVSS v3 Score 6.8
Products affected by CVE-2022-32962
-
cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30306
-
cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30404
-
cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.1.0.00002