CVE-2022-22572: High severity ivanti incapptic connect vulnerability
A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22572?
CVE-2022-22572 is a vulnerability that allows a non-admin user with user management permission to escalate their privilege to an admin user using the password reset functionality in Incapptic Connect version < 1.40.1.
What is the severity of CVE-2022-22572?
The severity of CVE-2022-22572 is high, with a severity value of 8.8.
Which software version is affected by CVE-2022-22572?
CVE-2022-22572 affects Incapptic Connect version < 1.40.1.
How can a non-admin user exploit CVE-2022-22572?
A non-admin user with user management permission can exploit CVE-2022-22572 by using the password reset functionality to escalate their privilege to an admin user.
Is there a fix available for CVE-2022-22572?
A fix for CVE-2022-22572 is available by updating to Incapptic Connect version 1.40.2 or newer.