CVE-2022-36443: High severity zebra enterprise home screen vulnerability
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wireless and SD card) but it is still possible to use a physical connection (Ethernet cable) without restriction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36443?
The severity of CVE-2022-36443 is high with a severity value of 7.8.
What is Zebra Enterprise Home Screen?
Zebra Enterprise Home Screen is a software used for managing the user interface on Zebra mobile devices.
How does CVE-2022-36443 affect Zebra Enterprise Home Screen?
CVE-2022-36443 allows an attacker to use a physical connection (Ethernet cable) without restriction, despite locking some communication channels in Zebra Enterprise Home Screen.
Is there a fix available for CVE-2022-36443?
It is advised to update Zebra Enterprise Home Screen to the latest version to mitigate the vulnerability.
Where can I find more information about CVE-2022-36443?
You can find more information about CVE-2022-36443 on the Excellium Services advisory page (https://excellium-services.com/cert-xlm-advisory/CVE-2022-36443) and the Zebra Enterprise Home Screen website (https://www.zebra.com/us/en/products/software/mobile-computers/mobile-app-utilities/enterprise-home-screen.html).