CVE-2022-32962

MEDIUM

HiCOS Natural Person Credential Component Client - Unauthenticated Double Free

Title source: llm
STIX 2.1

Description

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-6293-86576-1.html

Scores

CVSS v3 6.8
EPSS 0.0022
EPSS Percentile 11.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (3)
hinet/hicos_natural_person_credential_component_client 3.0.3.30306
hinet/hicos_natural_person_credential_component_client 3.0.3.30404
hinet/hicos_natural_person_credential_component_client 3.1.0.00002
Published Jul 20, 2022
Tracked Since Feb 18, 2026