CVE-2022-22823 is a critical integer overflow vulnerability (CWE-190) in the build_model function of xmlparse.c within Expat (libexpat) versions prior to 2.4.3, affecting products like Debian, Siemens, and Tenable. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows unauthenticated attackers to achieve high impact on confidentiality, integrity, and availability over the network with low attack complexity. While it has a low EPSS score and is not in CISA's KEV catalog, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and community discussion and media coverage are minimal, indicating no active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.3CPE matchmatch criteria | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | ||
< 8.15.3CPE matchmatch criteria | cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.1.1CPE matchmatch criteria | cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022expat: Integer overflow in build_model in xmlparse.c
Jan 15, 2022build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Jan 11, 2022