go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

HWA JIUH DIGITAL TECHNOLOGY LTD. EasyTest Incorrect Authorization

TVN ID TVN-202212003
CVE ID CVE-2022-43438
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products HWA JIUH DIGITAL TECHNOLOGY LTD. EasyTest ver.17L18S~ver.22H29
Description The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access restrictions, to make API functions calls, manipulate system and terminate service.
Solution Update Easytest version to v.22I26
Credit Pin Wei, He (CHT Security)
Public Date 2022-12-30
Top