Medium severity6.8NVD Advisory· Published Jul 20, 2022· Updated Jun 17, 2026
CVE-2022-32962
CVE-2022-32962
Description
HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30306:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30306:*:*:*:*:linux:*:*
- cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.0.3.30404:*:*:*:*:macos:*:*
- cpe:2.3:a:hinet:hicos_natural_person_credential_component_client:3.1.0.00002:*:*:*:*:windows:*:*
- HINET/HiCOS’ client-side citizen digital certificatev5Range: unspecified
Patches
Vulnerability mechanics
References
1- www.twcert.org.tw/tw/cp-132-6293-86576-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.