This page lists publicly disclosed CVE vulnerabilities affecting changingtec rava_certificate_validation_system (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2022-39058 | RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files. | [email protected] | 7.5 | 1.68% | 2022-10-18 | 2026-06-17 |
| CVE-2022-39057 | RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perform arbitrary system command and disrupt service. | [email protected] | 7.2 | 0.69% | 2022-10-18 | 2026-06-17 |
| CVE-2022-39056 | RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database. | [email protected] | 9.8 | 0.76% | 2022-10-18 | 2026-06-17 |
| CVE-2022-39055 | RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response. | [email protected] | 5.3 | 0.41% | 2022-10-18 | 2026-06-17 |