CVE-2022-32272: Critical severity opswat metadefender vulnerability
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32272?
CVE-2022-32272 is a vulnerability in OPSWAT MetaDefender Core, MetaDefender ICAP, and MetaDefender Email Gateway that allows incorrect access control and results in privilege escalation.
What is the severity of CVE-2022-32272?
CVE-2022-32272 has a severity level of critical with a CVSS score of 9.8.
Which versions of OPSWAT MetaDefender are affected by CVE-2022-32272?
OPSWAT MetaDefender versions up to and exclusive of 5.1.2 are affected by CVE-2022-32272.
How does CVE-2022-32272 impact OPSWAT MetaDefender Core?
CVE-2022-32272 allows incorrect access control in OPSWAT MetaDefender Core, resulting in privilege escalation.
How can CVE-2022-32272 be fixed?
To fix CVE-2022-32272, update OPSWAT MetaDefender Core, MetaDefender ICAP, and MetaDefender Email Gateway to versions beyond 5.1.2.