CVE-2022-34824

Severity
9.8CRITICAL
EPSS
1.4%
top 19.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 8
Latest updateJul 22

Description

Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system and to potentially execute arbitrary code.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5nec_corporation/clusterpro_xCLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier

🔴Vulnerability Details

3
OSV
fdkaac vulnerabilities2025-07-22
GHSA
GHSA-jw3w-3gxw-82qw: Weak File and Folder Permissions vulnerability in CLUSTERPRO X 52022-11-09
CVEList
CVE-2022-34824: Weak File and Folder Permissions vulnerability in CLUSTERPRO X 52022-11-08
CVE-2022-34824 (CRITICAL CVSS 9.8) | Weak File and Folder Permissions vu | cvebase.io