Privilege Escalation Vulnerability in Suprema BioStar 2 Software
CVE-2022-38351

8.8HIGH

Key Information:

Vendor

Supremainc

Status
Vendor
CVE Published:
19 September 2022

What is CVE-2022-38351?

A significant security issue exists in Suprema BioStar 2 (version 2.8.16) that permits attackers to escalate their privileges to those of a System Administrator. This is achieved through a specially crafted PUT request directed at the update profile page. If exploited, this vulnerability could allow unauthorized users to gain elevated access within the system, potentially compromising sensitive data and system integrity.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.