CVE-2022-3686: SDM600 API permission check
A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the application unresponsive. This issue affects: All SDM600 versions prior to version 1.2 FP3 HF4 (Build Nr. 1.2.23000.291)
List of CPEs:
cpe:2.3:a:hitachienergy:sdm600:1.0::::::: cpe:2.3:a:hitachienergy:sdm600:1.1::::::: cpe:2.3:a:hitachienergy:sdm600:1.2::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.9002.257::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.10002.257::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.11002.149::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.12002.222::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.13002.72::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.44::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.92::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.108::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.182::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.257::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.342::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.447::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.481::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.506::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.14002.566::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.20000.3174::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.21000.291::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.21000.931::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.21000.105::::::: cpe:2.3:a:hitachienergy:sdm600:1.2.23000.291:::::::
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-3686?
CVE-2022-3686 is a vulnerability that exists in a SDM600 endpoint, allowing attackers to render the application unresponsive by running multiple parallel requests.
How does CVE-2022-3686 affect SDM600?
CVE-2022-3686 affects all SDM600 versions prior to version 1.2 FP3 HF4 (Build Nr. 1.2.23000.291) by making the web services busy and unresponsive.
What is the severity of CVE-2022-3686?
CVE-2022-3686 has a severity rating of 9.1, classified as critical.
How can an attacker exploit CVE-2022-3686?
An attacker can exploit CVE-2022-3686 by running multiple parallel requests to overload the SDM600 web services.
Is there a fix for CVE-2022-3686?
Yes, the fix for CVE-2022-3686 is to upgrade SDM600 to version 1.2 FP3 HF4 (Build Nr. 1.2.23000.291) or later.