CVE-2022-44565

An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
hackeroneCNA
---
---
CVEADP
---
---
CISA-ADPADP
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
uiairfiber_gigabeam_firmware
𝑥
< 1.4.1
uiairfiber_60-xg_firmware
𝑥
< 1.0.0
uiairfiber_60-hd_firmware
𝑥
< 1.0.0
uiairfiber_60-lr_firmware
𝑥
< 2.6.2
uiairmax_ac_firmware
𝑥
< 8.7.11
uiairfiber_60_firmware
𝑥
< 2.6.2
𝑥
= Vulnerable software versions