CVE-2022-35629

MEDIUM

Velociraptor < 0.6.5-2 - Authentication Bypass by Client ID Spoofing

Title source: llm
STIX 2.1

Description

Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved in Velociraptor 0.6.5-2.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0040
EPSS Percentile 31.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-290 CWE-287
Status published
Products (1)
rapid7/velociraptor < 0.6.5-2
Published Jul 29, 2022
Tracked Since Feb 18, 2026