A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
CVE-2022-30605
HIGHNVD 8.88.8—Trending — 3 sources updated this weekElevated
EchelonGraph scoreMEDIUM confidence
Score 8.8 from GitHub Security Advisory (severity: HIGH) published 2022-08-23. NVD baseline CVSS 8.8; sources differ by 0.0.
Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
8.8
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
- High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS: 4%CVSS: 8.8Exploit: NoneExposed: 0
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.8
- EG Score
- 8.8(medium)
- EG Risk
- —
- EPSS
- 89.7%
- KEV
- Not listed
Published
August 22, 2022
Last Modified
November 21, 2024
References (4)
- talos-cna@ciscohttps://github.com/WWBN/AVideo/blob/e04b1cd7062e16564157a82bae389eedd39fa088/updatedb/updateDb.v12.0.sql
- talos-cna@ciscohttps://talosintelligence.com/vulnerability_reports/TALOS-2022-1535
- af854a3a-2127-422b-91ae-364da2661108https://github.com/WWBN/AVideo/blob/e04b1cd7062e16564157a82bae389eedd39fa088/updatedb/updateDb.v12.0.sql
- af854a3a-2127-422b-91ae-364da2661108https://talosintelligence.com/vulnerability_reports/TALOS-2022-1535
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Frequently asked(5)
What is CVE-2022-30605?
CVE-2022-30605 is a high vulnerability published on August 22, 2022. A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
When was CVE-2022-30605 disclosed?
CVE-2022-30605 was first published in the National Vulnerability Database on August 22, 2022, with the most recent update on November 21, 2024. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2022-30605 actively exploited?
CVE-2022-30605 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 89.7% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2022-30605?
CVE-2022-30605 has a CVSS v3 base score of 8.8 (NVD).
How do I remediate CVE-2022-30605?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2022-30605, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2022-30605
Is Your Infrastructure Affected by CVE-2022-30605?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.