CVE-2022-32962

MEDIUM

HiCOS - Use After Free

Title source: llm

Description

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

Scores

CVSS v3 6.8
EPSS 0.0007
EPSS Percentile 21.5%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status published

Affected Products (3)

hinet/hicos_natural_person_credential_component_client
hinet/hicos_natural_person_credential_component_client
hinet/hicos_natural_person_credential_component_client

Timeline

Published Jul 20, 2022
Tracked Since Feb 18, 2026