CVE-2022-32962: HiCOS’ client-side citizen digital certificate - Double Free
HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32962?
The severity of CVE-2022-32962 is rated as medium with a CVSS score of 6.8.
How do I fix CVE-2022-32962?
To fix CVE-2022-32962, download and install the latest version of the HiCOS client.
What types of systems are affected by CVE-2022-32962?
CVE-2022-32962 affects HiNet Hicos Natural Person Credential Component Client on Linux, MacOS, and Windows.
What is the impact of exploiting CVE-2022-32962?
Exploiting CVE-2022-32962 can lead to memory corruption, arbitrary code execution, manipulation of system data, or service termination.
Is CVE-2022-32962 exploited remotely?
CVE-2022-32962 requires physical access to the system for exploitation, as it is an unauthenticated vulnerability.