CRITICAL

CVE-2022-24702

CVSS v3

9.8

CRITICAL

EPSS Score

40.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Technical details

Published
6/2/2022

Frequently asked questions

What is CVE-2022-24702?

An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Is CVE-2022-24702 actively exploited?

Active exploitation of CVE-2022-24702 has not been confirmed. The EPSS score is 40.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-24702?

CVE-2022-24702 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-24702 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.