6.8
CVSSv2

CVE-2022-28944

Published: 23/05/2022 Updated: 07/06/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

emcosoftware network_inventory 5.8.22

emcosoftware network_software_scanner 2.0.8

emcosoftware unlock_it 6.1.1

emcosoftware remote_shutdown 7.2.2

emcosoftware ping_monitor 8.0.18

emcosoftware msi_package_builder 9.1.4

emcosoftware remote_installer 6.0.13

emcosoftware wakeonlan 2.0.8

Github Repositories

CVE-2022-28944 EMCO Software Multiple Products Unauthenticated Update Remote Code Execution Vulnerability Usage: python3 cve-2022-28944_pocpy Details in the report at gerrre Steps to reproduce Install an affected product of EMCO Software; Set spoof storageemcosoftwarecom to our attacker ip; For a proof-of-concept edit c:\windows\system32\drivers\etc\hosts on target