CVE-2022-32962
MEDIUMHiCOS - Use After Free
Title source: llmDescription
HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.
Scores
CVSS v3
6.8
EPSS
0.0007
EPSS Percentile
21.5%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-415
Status
published
Affected Products (3)
hinet/hicos_natural_person_credential_component_client
hinet/hicos_natural_person_credential_component_client
hinet/hicos_natural_person_credential_component_client
Timeline
Published
Jul 20, 2022
Tracked Since
Feb 18, 2026