CVE-2022-32282: High severity wwbn avideo vulnerability
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' password hash will be able to use it to directly login into the account, leading to increased privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32282?
CVE-2022-32282 has been classified with a medium severity level due to the risk of unauthorized access to user accounts.
How does CVE-2022-32282 affect user accounts?
CVE-2022-32282 allows an attacker with a user's password hash to log in directly to their account, resulting in unauthorized access.
How do I fix CVE-2022-32282?
To mitigate CVE-2022-32282, ensure that password hashes are not directly usable for authentication by implementing proper security measures.
Is CVE-2022-32282 present in all versions of WWBN AVideo?
No, CVE-2022-32282 specifically affects WWBN AVideo version 11.6 and the development master commit 3f7c0364.
What can be done to secure accounts affected by CVE-2022-32282?
Users should update their passwords and review their account activity regularly to secure their accounts against CVE-2022-32282.