CVSS v3
9.8
CRITICAL
EPSS Score
25.2%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.
Active exploitation of CVE-2022-34970 has not been confirmed. The EPSS score is 25.2%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2022-34970 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).