nhi CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

nhi vulnerability overview

Aggregates CVE and security vulnerability intelligence across all nhi-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk memory corruption and vendor risk buffer overflow and related problems; some flaws may lead to vendor impact memory corruption, affecting vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-35219 The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service. [email protected] 5.5 0.18% 2022-08-02 2024-11-21
CVE-2022-35218 The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service. [email protected] 5.5 0.18% 2022-08-02 2024-11-21
CVE-2022-35217 The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service. [email protected] 7.8 0.22% 2022-08-02 2024-11-21
CVE-2021-45918 NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which requires a system restart to recover service. [email protected] 7.5 1.39% 2022-06-20 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence