CVE-2022-39061

MEDIUM

ChangingTech MegaServiSignAdapter - Memory Corruption

Title source: llm
STIX 2.1

Description

ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for parameter length. An unauthenticated remote attacker can exploit this vulnerability to access partial sensitive content in memory and disrupts partial services.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0033
EPSS Percentile 55.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (1)
changingtec/megaservisignadapter < 1.0.22.1004
Published Jan 31, 2023
Tracked Since Feb 18, 2026