CVE-2022-35629

MEDIUM

Velociraptor < 0.6.5-2 - Authentication Bypass by Client ID Spoofing

Title source: llm
STIX 2.1

Description

Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved in Velociraptor 0.6.5-2.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0043
EPSS Percentile 35.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-287 CWE-290
Status published
Products (1)
rapid7/velociraptor < 0.6.5-2
Published Jul 29, 2022
Tracked Since Feb 18, 2026