High severity7.5NVD Advisory· Published Jul 25, 2023· Updated Jun 17, 2026
CVE-2022-46901
CVE-2022-46901
Description
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and backing up, loading, and clearing of the database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:vocera:report_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vocera:report_server:*:*:*:*:*:*:*:*range: >=5.0.0,<=5.8.0.135
- (no CPE)range: 5.x - 5.8
cpe:2.3:a:vocera:voice_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vocera:voice_server:*:*:*:*:*:*:*:*range: >=5.0.0,<=5.8.0.135
- (no CPE)range: 5.x - 5.8
- Vocera/Report Server and Voice Serverdescription
- Range: 5.x - 5.8
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.