CVE-2022-27438
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD
Description
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
Affected (70)
Products: Caphyon: Advanced Installer · 3cx: Call Flow Designer, Crm Template Generator · Boom: Boomtv Streamer Portal · +26 more
Show all products
Caphyon: Advanced Installer · 3cx: Call Flow Designer, Crm Template Generator · Boom: Boomtv Streamer Portal · Codesector: Direct Folders, Teracopy · Emeditor: Emeditor · Flamory: Flamory · Freesnippingtool: Free Snipping Tool · Fxsound: Fxsound · Gainedge: Better Explorer · Gamecaster: Gamecaster · Getmailbird: Mailbird · Guzogo: Guzogo · Honeygain: Honeygain · Jki: Vi Package Manager · Jpsoft: Take Command · Krylack: Archive Password Recovery, Asterisks Password Decryptor, Burning Suite, Rar Password Recovery, Volume Serial Number Editor, Zip Password Recovery · Moonsoftware: Password Agent · Nefarius: Scptoolkit · Plagiarismcheckerx: Plagiarism Checker X · Prusa3d: Prusaslicer · Realdefense: Mycleanid, Mycleanpc, Mypasslock · Rovio: Angry Birds Space, Bad Piggies · Synaptics: Displaylink Usb Graphics · Urban Vpn: Urban Vpn · Vigem: Vigembus Driver · Vpnhood: Vpnhood · Vrdesktop: Virtual Desktop Streamer · Xsplit: Xsplit Express Video Editor · Rstinstruments: Vw0420 Firmware, Inclinalysis Digital Inclinometer, Ipi Utility, Rstar Rtu Host, Dt2011 Firmware, Dt2011b Firmware, Dt2040 Firmware, Dt2050 Firmware, Dt2050b Firmware, Dt2055b Firmware, Dt2306 Firmware, Dt2350 Firmware, Dt2485 Firmware, Dt4205 Firmware, Dtsaa Firmware, Ic6560 Firmware, Ic6660 Firmware, Dtl201b/2b Firmware, Mtcm Firmware, Gaa2820 Firmware, Rtu Firmware, Mems Tilt Meter Firmware, Portable Tilt Meter Firmware, Vw2106 Firmware, Th2016 Firmware, Th2016b Firmware, Ma7 Firmware, Qb120 Firmware, Sg350 Firmware, Ir420 Firmware, Lp100 Firmware, C109 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 19.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 18.2.13 | |
| Version 2.1.23 | |
| Version 2.2.1 | |
| Version 4.0 | |
| Version 3.8.5 | |
| Version 21.3.0 | |
| Version 4.2.19.0 | |
| Version 5.6.0.0 | |
| Version 1.1.12.0 | |
| Version 2020.3.15.1304 | |
| Version 4.0.2109.2802 | |
| Version 2.9.50.0 | |
| Version 1.0.5.0 | |
| Version 0.10.7.0 | |
| Version 21.1.2754 | |
| Version 28.2.18 | |
| Version 3.70.69 | |
| Version 3.31.107 | |
| Version 1.20.05 | |
| Version 3.70.69 | |
| Version 2.02.34 | |
| Version 3.70.69 | |
| Version 20.10.1 | |
| Version 1.6.238.16010 | |
| Version 8.0.6 | |
| Version 2.4.2 | |
| Version 4.1.4 | |
| Version 4.0.2 | |
| Version 1.9.6 | |
| Version 1.4.1 | |
| Version 1.3.0 | |
| Before 10.3.6400.0 | |
| Version 2.2.5 | |
| Version 1.16.116 | |
| Version 2.4.299 | |
| Version 1.20.16 | |
| Version 3.0.2001.801 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.33.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Vw0420 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.48.9 | |
| Version 1.05.0 | |
| Version 1.33.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt2011 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt2011b | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt2040 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt2050 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt2050b | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt2055b | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt2306 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt2350 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt2485 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dt4205 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dtsaa | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Ic6560 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Ic6660 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Dtl201b/2b | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Mtcm | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Gaa2820 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.19.4.0 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Rtu | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.20.1 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Mems Tilt Meter | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.20.1 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Portable Tilt Meter | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Vw2106 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0.2 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Th2016 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0.2 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Th2016b | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0.2 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Ma7 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0.2 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Qb120 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0.2 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Sg350 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0.2 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Ir420 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0.2 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments Lp100 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0.2 |
| Running on/with | Platform Versions |
|---|---|
Rstinstruments C109 | All versions |
References (8)
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.