| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2022-40674 | 0.0 | unknown |
CVE-2022-40674. Local users can write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
|
| CVE-2022-43680 | 0.0 | unknown |
CVE-2022-43680. In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
|
| Vendor | Product | Asset Type | Purdue Level | Firmware |
|---|---|---|---|---|
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |