CVE-2022-32965

CRITICAL

OMICARD EDM - Remote Code Execution

Title source: llm
STIX 2.1

Description

OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate system data and disrupt service.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-6373-34d51-1.html

Scores

CVSS v3 9.8
EPSS 0.0114
EPSS Percentile 62.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
omicard_edm_project/omicard_edm 5.8 - 6.0
Published Aug 04, 2022
Tracked Since Feb 18, 2026