Known vulnerabilities in Autodesk Infraworks 2022.1.5 Hotfix 5 - page 2

Vendor: Autodesk
Version: 2022.1.5 Hotfix 5
Software CPE: cpe:2.3:a:autodesk:autodesk_infraworks:*:*:*:*:*:*:*:*
Total vulnerabilities: 48
Public exploits: 7
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Autodesk Infraworks version 2022.1.5 Hotfix 5 Autodesk Infraworks 2022.1.5 Hotfix 5 is affected by 48 vulnerabilities: 1 critical, 7 high, 25 medium, 15 low Critical High Medium Low

Vulnerabilities (48)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73175 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-31159
CWE-22 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 08.03.2023 SB2023030823
SB2023030915
SB2023042635
and 15 more
#VU72076 - Incorrect Authorization
CVE-2020-7692
CWE-863 High
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 08.02.2023 SB2020070955
SB2023020889
SB2023022307
and 9 more
#VU64524 - Improper Neutralization of Special Elements used in an Expression Language Statement
CVE-2022-22980
CWE-917 High
Public exploit available
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 21.06.2022 SB2022062101
SB2022112938
SB2023042635
and 2 more
#VU64471 - Improper Verification of Cryptographic Signature
CVE-2021-22573
CWE-347 Low
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 17.06.2022 SB2022061720
SB2022061804
SB2022062732
and 14 more
#VU63127 - Resource exhaustion
CVE-2021-37136
CWE-400 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 12.05.2022 SB2021101948
SB2022051235
SB2022060838
and 36 more
#VU61810 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-43797
CWE-444 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 02.04.2022 SB2021120923
SB2022040202
SB2022042223
and 49 more
#VU60986 - Improper input validation
CVE-2020-28491
CWE-20 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 03.03.2022 SB2022030316
SB2022030322
SB2022062413
and 12 more
#VU59924 - Improper input validation
CVE-2021-37137
CWE-20 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 23.01.2022 SB2022012310
SB2022012745
SB2022012753
and 43 more
#VU51836 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-21295
CWE-444 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 01.04.2021 SB2021040115
SB2021040626
SB2021050706
and 26 more
#VU51835 - Cleartext Storage of Sensitive Information
CVE-2021-21290
CWE-312 Low
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 01.04.2021 SB2021020813
SB2021040626
SB2021050706
and 42 more
#VU49739 - Improper input validation
CVE-2020-5421
CWE-20 Medium
Public exploit available
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 20.01.2021 SB2021012002
SB2021012008
SB2021012015
and 39 more
#VU28773 - Use After Free
CVE-2020-13871
CWE-416 High
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 07.06.2020 SB2020060705
SB2020072756
SB2020102002
and 8 more
#VU25355 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2019-20444
CWE-444 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 14.02.2020 SB2020012928
SB2020022601
SB2020031305
and 36 more
#VU25353 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-7238
CWE-444 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 14.02.2020 SB2020021409
SB2020022521
SB2020022601
and 16 more
#VU24066 - Resource Management Errors
CVE-2019-19924
CWE-399 Low
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 07.01.2020 SB2019122301
SB2020042838
SB2022031104
and 7 more
#VU23189 - Improper input validation
CVE-2019-19242
CWE-20 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 02.12.2019 SB2019120211
SB2019120212
SB2019121736
and 4 more
#VU22825 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2019-16869
CWE-444 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 18.11.2019 SB2019092616
SB2019111903
SB2019112016
and 30 more
#VU18060 - NULL Pointer Dereference
CVE-2019-9937
CWE-476 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 22.03.2019 SB2019032205
SB2019051006
SB2019081527
and 7 more
#VU15467 - Improper input validation
CVE-2018-15756
CWE-20 Low
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 22.10.2018 SB2018102305
SB2020012203
SB2020032701
and 28 more
#VU11918 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2018-1273
CWE-113 High
Public exploit available
Exploited
2021.2 Hotfix 9, 2023.1 Hotfix 1 18.04.2018 SB2018041815
SB2022072013
SB2023011758
and 2 more


Showing elements 21 - 40 out of 48