Vulnerability Details CVE-2022-42951
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using default credentials.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.5%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2022-42951
-
cpe:2.3:a:couchbase:couchbase_server:6.5.0
-
cpe:2.3:a:couchbase:couchbase_server:6.5.1
-
cpe:2.3:a:couchbase:couchbase_server:6.5.2
-
cpe:2.3:a:couchbase:couchbase_server:6.6.0
-
cpe:2.3:a:couchbase:couchbase_server:6.6.1
-
cpe:2.3:a:couchbase:couchbase_server:6.6.2
-
cpe:2.3:a:couchbase:couchbase_server:6.6.3
-
cpe:2.3:a:couchbase:couchbase_server:7.0.0
-
cpe:2.3:a:couchbase:couchbase_server:7.0.1
-
cpe:2.3:a:couchbase:couchbase_server:7.0.2
-
cpe:2.3:a:couchbase:couchbase_server:7.0.3
-
cpe:2.3:a:couchbase:couchbase_server:7.0.4
-
cpe:2.3:a:couchbase:couchbase_server:7.1.0
-
cpe:2.3:a:couchbase:couchbase_server:7.1.1