CVE-2022-34866 - CVE House
Back to Database
Status published High CVE-2022-34866

Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for...

Vulnerability Description

Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verification vulnerability for interprocess communication. By running a malicious program, an arbitrary OS command may be executed with LocalSystem privilege of the Windows system where the product is running.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-34866

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Yokogawa Rental & Lease Corporation

View all reports →

Affected Software

Passage Drive
Vulnerable Versions:
Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0

Timeline

Official Publish: July 20th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.