VYPR

MegaServiSignAdapter

by Changingtec

CVEs (3)

  • CVE-2022-39060CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take…

  • CVE-2022-39059HigJan 31, 2023
    risk 0.49cvss 7.5epss 0.01

    ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.

  • CVE-2022-39061MedJan 31, 2023
    risk 0.42cvss 6.5epss 0.01

    ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for parameter length. An unauthenticated remote attacker can exploit this vulnerability to access partial sensitive content in memory and disrupts partial…