CVE-2022-22570
published 2022-04-01CVE-2022-22570: A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who…
PriorityP261critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
1.03%
59.3th percentile
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devices. This vulnerability is fixed in Version 3.8.31.13 and later.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ui | ua_lite_firmware | < 3.8.31.13 | 3.8.31.13 |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle7.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qc3q-358p-q5mv: A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3
ghsa_unreviewed·2022-04-03
CVE-2022-22570 [CRITICAL] CWE-120 GHSA-qc3q-358p-q5mv: A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devices. This vulnerability is fixed in Version 3.8.31.13 and later.
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Compiling (protobuf) — CVE-2021-22570
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2021-22570 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Server: Compiling (protobuf) — CVE-2021-22570
Oracle Oracle MySQL Risk Matrix: Server: Compiling (protobuf) vulnerability
CVE: CVE-2021-22570
CVSS: 7.5
Protocol: MySQL Protocol
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-01
Published