CVE-2022-32273: Medium severity opswat metadefender vulnerability
Published Jun 8, 2022
·Updated
As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.
Affected Software
1 affected component
OPSWAT MetaDefender<5.1.2
Event History
Jun 8, 2022
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
Description
Frequently Asked Questions
1
What is CVE-2022-32273?
CVE-2022-32273 is a vulnerability in OPSWAT MetaDefender Core (MDCore) before version 5.1.2 that allows an authenticated user to enumerate filenames on the server due to an observable discrepancy in returned messages.
2
How severe is CVE-2022-32273?
CVE-2022-32273 has a severity score of 4.3 (medium).
3
How can I fix CVE-2022-32273?
To fix CVE-2022-32273, you should update OPSWAT MetaDefender Core (MDCore) to version 5.1.2 or later.
4
Where can I find more information about CVE-2022-32273?
You can find more information about CVE-2022-32273 in the release notes of OPSWAT MetaDefender Core (MDCore) and on the OPSWAT website.
5
What is the CWE ID for CVE-2022-32273?
The CWE ID for CVE-2022-32273 is 203.