Microsoft Azure Site Recovery vulnerabilities

38 known vulnerabilities affecting microsoft/azure_site_recovery.

Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM22

Vulnerabilities

Page 2 of 2
CVE-2022-33677HIGHCVSS 7.2fixed in 9.49.6395.12022-07-12
CVE-2022-33677 [HIGH] CVE-2022-33677: Azure Site Recovery Elevation of Privilege Vulnerability Azure Site Recovery Elevation of Privilege Vulnerability
nvd
CVE-2022-33678HIGHCVSS 7.2fixed in 9.49.6395.12022-07-12
CVE-2022-33678 [HIGH] CVE-2022-33678: Azure Site Recovery Remote Code Execution Vulnerability Azure Site Recovery Remote Code Execution Vulnerability
nvd
CVE-2022-30181MEDIUMCVSS 6.5fixed in 9.492022-07-12
CVE-2022-30181 [MEDIUM] CVE-2022-30181: Azure Site Recovery Elevation of Privilege Vulnerability Azure Site Recovery Elevation of Privilege Vulnerability
nvd
CVE-2022-26898HIGHCVSS 7.2fixed in 9.482022-04-15
CVE-2022-26898 [HIGH] CVE-2022-26898: Azure Site Recovery Remote Code Execution Vulnerability Azure Site Recovery Remote Code Execution Vulnerability
nvd
CVE-2022-26897MEDIUMCVSS 4.9fixed in 9.482022-04-15
CVE-2022-26897 [MEDIUM] CVE-2022-26897: Azure Site Recovery Information Disclosure Vulnerability Azure Site Recovery Information Disclosure Vulnerability
nvd
CVE-2022-26896MEDIUMCVSS 4.9fixed in 9.482022-04-15
CVE-2022-26896 [MEDIUM] CVE-2022-26896: Azure Site Recovery Information Disclosure Vulnerability Azure Site Recovery Information Disclosure Vulnerability
nvd
CVE-2022-24471HIGHCVSS 7.2fixed in 9.47.6219.12022-03-09
CVE-2022-24471 [HIGH] CVE-2022-24471: Azure Site Recovery Remote Code Execution Vulnerability Azure Site Recovery Remote Code Execution Vulnerability
nvd
CVE-2022-24517HIGHCVSS 7.2fixed in 9.47.6219.12022-03-09
CVE-2022-24517 [HIGH] CVE-2022-24517: Azure Site Recovery Remote Code Execution Vulnerability Azure Site Recovery Remote Code Execution Vulnerability
nvd
CVE-2022-24470HIGHCVSS 7.2fixed in 9.47.6219.12022-03-09
CVE-2022-24470 [HIGH] CVE-2022-24470: Azure Site Recovery Remote Code Execution Vulnerability Azure Site Recovery Remote Code Execution Vulnerability
nvd
CVE-2022-24506HIGHCVSS 7.2fixed in 9.47.6219.12022-03-09
CVE-2022-24506 [MEDIUM] CVE-2022-24506: Azure Site Recovery Elevation of Privilege Vulnerability Azure Site Recovery Elevation of Privilege Vulnerability
nvd
CVE-2022-24515HIGHCVSS 7.2fixed in 9.47.6219.12022-03-09
CVE-2022-24515 [MEDIUM] CVE-2022-24515: Azure Site Recovery Elevation of Privilege Vulnerability Azure Site Recovery Elevation of Privilege Vulnerability
nvd
CVE-2022-24520HIGHCVSS 7.2fixed in 9.47.6219.12022-03-09
CVE-2022-24520 [HIGH] CVE-2022-24520: Azure Site Recovery Remote Code Execution Vulnerability Azure Site Recovery Remote Code Execution Vulnerability
nvd
CVE-2022-24468HIGHCVSS 7.2fixed in 9.47.6219.12022-03-09
CVE-2022-24468 [HIGH] CVE-2022-24468: Azure Site Recovery Remote Code Execution Vulnerability Azure Site Recovery Remote Code Execution Vulnerability
nvd
CVE-2022-24467HIGHCVSS 7.2fixed in 9.47.6219.12022-03-09
CVE-2022-24467 [HIGH] CVE-2022-24467: Azure Site Recovery Remote Code Execution Vulnerability Azure Site Recovery Remote Code Execution Vulnerability
nvd
CVE-2022-24469HIGHCVSS 8.8fixed in 9.47.6219.12022-03-09
CVE-2022-24469 [HIGH] CVE-2022-24469: Azure Site Recovery Elevation of Privilege Vulnerability Azure Site Recovery Elevation of Privilege Vulnerability
nvd
CVE-2022-24519MEDIUMCVSS 4.9fixed in 9.47.6219.12022-03-09
CVE-2022-24519 [MEDIUM] CVE-2022-24519: Azure Site Recovery Elevation of Privilege Vulnerability Azure Site Recovery Elevation of Privilege Vulnerability
nvd
CVE-2022-24518MEDIUMCVSS 4.9fixed in 9.47.6219.12022-03-09
CVE-2022-24518 [MEDIUM] CVE-2022-24518: Azure Site Recovery Elevation of Privilege Vulnerability Azure Site Recovery Elevation of Privilege Vulnerability
nvd
CVE-2021-42306MEDIUMCVSS 6.5vN/A2021-11-24
CVE-2021-42306 [HIGH] CWE-522 CVE-2021-42306: An information disclosure vulnerability manifests when a user or an application uploads unprotected An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private
cvelistv5nvd