peter bassill · operator
$ cve CVE-2022-34598 JSON

CVE-2022-34598

9.8
CRITICAL · CVSS 3.1 · EPSS 7.2% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.19% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploitnone known
Published2022-07-06
Last modified2026-06-17

Affected (2)

VendorProduct
h3cmagic r100
h3cmagic r100 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD