Known vulnerabilities in Autodesk Infraworks 2022.1 Hotfix 3 - page 2
Vendor:
Autodesk
Software:
Autodesk Infraworks
Version:
2022.1 Hotfix 3
Software CPE:
cpe:2.3:a:autodesk:autodesk_infraworks:*:*:*:*:*:*:*:*
Website:
https://www.autodesk.com/
Total vulnerabilities:
61
Public exploits:
8
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
2026.3
2026.2
2026.1
2026.0
2022.1.10.363
2023.1.5.251
2024.1.4.152
2025.02.86
2021.2 Hotfix 9
2023.1 Hotfix 1
2023.0.2
2023.0.1 Hotfix 1
2023.0.1
2022.1.5 Hotfix 5
2022.1.5
2021.2 Hotfix 7
2020.2 Hotfix 7
2022.1 Hotfix 4
2022.1 Hotfix 3
2022.1 Hotfix 1
2021.2 Hotfix 6
2021.2 Hotfix 5
2021.2 Hotfix 3
2021.2 Hotfix 2
2021.2 Hotfix 1
2020.2 Hotfix 6
2020.2 Hotfix 5
2020.2 Hotfix 3
2020.2 Hotfix 2
2020.2 Hotfix 1
2019.3 Hotfix 5
2020.2 Hotfix 4
2021.2 Hotfix 4
2022.0 Hotfix 3
2022.1 Hotfix 2
2019.3
2020.2
2021.2
2022.1
2022.0
Vulnerabilities (61)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU72076 - Incorrect Authorization CVE-2020-7692 |
CWE-863 | High | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 08.02.2023 |
SB2020070955 SB2023020889 SB2023022307 and 9 more |
||
| #VU64524 - Improper Neutralization of Special Elements used in an Expression Language Statement CVE-2022-22980 |
CWE-917 | High | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 21.06.2022 |
SB2022062101 SB2022112938 SB2023042635 and 2 more |
||
| #VU64471 - Improper Verification of Cryptographic Signature CVE-2021-22573 |
CWE-347 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 17.06.2022 |
SB2022061720 SB2022061804 SB2022062732 and 14 more |
||
| #VU62849 - Creation of Temporary File With Insecure Permissions CVE-2022-24823 |
CWE-378 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 09.05.2022 |
SB2022050902 SB2022063002 SB2022072013 and 55 more |
||
| #VU61756 - Improper Control of Generation of Code ('Code Injection') CVE-2022-22965 |
CWE-94 | Critical | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 31.03.2022 |
SB2022033109 SB2022040109 SB2022040110 and 78 more |
||
| #VU60986 - Improper input validation CVE-2020-28491 |
CWE-20 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 03.03.2022 |
SB2022030316 SB2022030322 SB2022062413 and 12 more |
||
| #VU51835 - Cleartext Storage of Sensitive Information CVE-2021-21290 |
CWE-312 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 01.04.2021 |
SB2021020813 SB2021040626 SB2021050706 and 42 more |
||
| #VU28773 - Use After Free CVE-2020-13871 |
CWE-416 | High | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 07.06.2020 |
SB2020060705 SB2020072756 SB2020102002 and 8 more |
||
| #VU25861 - NULL Pointer Dereference CVE-2020-9327 |
CWE-476 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 10.03.2020 |
SB2020022121 SB2020031502 SB2020110913 and 15 more |
||
| #VU25355 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2019-20444 |
CWE-444 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 14.02.2020 |
SB2020012928 SB2020022601 SB2020031305 and 36 more |
||
| #VU25353 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-7238 |
CWE-444 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 14.02.2020 |
SB2020021409 SB2020022521 SB2020022601 and 16 more |
||
| #VU24066 - Resource Management Errors CVE-2019-19924 |
CWE-399 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 07.01.2020 |
SB2019122301 SB2020042838 SB2022031104 and 7 more |
||
| #VU24064 - Resource Management Errors CVE-2019-19959 |
CWE-399 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 07.01.2020 |
SB2019122301 SB2020042838 SB2022041131 and 6 more |
||
| #VU23794 - Untrusted Pointer Dereference CVE-2019-19880 |
CWE-822 | High | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 23.12.2019 |
SB2019122301 SB2020020601 SB2020020614 and 13 more |
||
| #VU23793 - Improper input validation CVE-2019-19926 |
CWE-20 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 23.12.2019 |
SB2019122301 SB2020020601 SB2020020614 and 14 more |
||
| #VU23790 - Improper input validation CVE-2019-19603 |
CWE-20 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 23.12.2019 |
SB2019122301 SB2022031104 SB2022041131 and 17 more |
||
| #VU23189 - Improper input validation CVE-2019-19242 |
CWE-20 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 02.12.2019 |
SB2019120211 SB2019120212 SB2019121736 and 4 more |
||
| #VU22825 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2019-16869 |
CWE-444 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 18.11.2019 |
SB2019092616 SB2019111903 SB2019112016 and 30 more |
||
| #VU18060 - NULL Pointer Dereference CVE-2019-9937 |
CWE-476 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 22.03.2019 |
SB2019032205 SB2019051006 SB2019081527 and 7 more |
||
| #VU18059 - Out-of-bounds read CVE-2019-9936 |
CWE-125 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 22.03.2019 |
SB2019032205 SB2019051006 SB2019081527 and 7 more |
Showing elements 21 - 40 out of 61