CVE-2022-30625 MEDIUM

CVE-2022-30625: Chcnav - P5E GNSS Directory listing

Vendor Chcnav
Product Chcnav - P5E GNSS
Weakness CWE-548 · Directory listing
Published July 18, 2022
Last update September 17, 2024

CVSS base score

5.7/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.

Key dates

02Disclosure timeline

July 18, 2022 CVE published
September 17, 2024 Record updated