CVE-2021-22314

Severity
7.8HIGH
EPSS
0.0%
top 93.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 22
Latest updateMay 24

Description

There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5manageone6.5.1.1.B010,6.5.1RC1.B060,6.5.1RC1.B070,6.5.1RC2.B020,6.5.1RC2.B030
NVDhuawei/manageone6.5.1, 6.5.1.1+1

🔴Vulnerability Details

2
GHSA
GHSA-xw65-87w9-v79c: There is a local privilege escalation vulnerability in some versions of ManageOne2022-05-24
CVEList
CVE-2021-22314: There is a local privilege escalation vulnerability in some versions of ManageOne2021-03-22