Unsafe Deserialization Vulnerability in HYPR Workforce Access
CVE-2022-1984

4.5MEDIUM

Key Information:

Vendor

Hypr

Vendor
CVE Published:
19 July 2022

What is CVE-2022-1984?

An unsafe deserialization vulnerability exists in HYPR Workforce Access (WFA) versions earlier than 7.2, which could permit local authenticated attackers to gain elevated privileges through the exploitation of malicious serialized payloads. This could potentially allow unauthorized access to sensitive functions and data, emphasizing the importance of updating to the latest version to mitigate associated risks.

Affected Version(s)

HYPR Windows WFA < 7.2

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.