CVE Database
/

CVE-2022-28719

Back to search

CVE-2022-28719

Published: Apr 28, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.

VendorProductVersions

Hammock Corporation

AssetView

affected
prior to Ver.13.2.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now