CVE-2022-23852 describes a critical signed integer overflow vulnerability in Expat (libexpat) versions prior to 2.4.4, specifically impacting configurations with a non-zero XML_CONTEXT_BYTES. This flaw affects a range of products including Debian, NetApp, Oracle, Siemens, and Tenable. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low attack complexity, requiring no user interaction, and can lead to complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score of 93/100 further highlights its severe potential impact. While not currently listed in CISA's KEV catalog and lacking public Metasploit or ExploitDB modules, the vulnerability has garnered significant community attention with 12 mentions and 2 media articles, suggesting active discussion and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.4CPE matchmatch criteria | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* | ||
< 8.15.3CPE matchmatch criteria | cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.1.1CPE matchmatch criteria | cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022Multiple ctrlX CORE vulnerabilities
Apr 20, 2022expat: Integer overflow in function XML_GetBuffer
Jan 23, 2022Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer for configurations with a nonzero XML_CONTEXT_BYTES.
Jan 11, 2022