← Back to browse · API

CVE-2022-3365

Severity
CRITICAL
CVSS
9.8
EPSS
0.0208
Risk score
39.93
CISA KEV
No
PoC
No
Published
2025-01-28
Modified
2025-01-28
First seen
2026-08-07
Aliases
EUVD-2022-42745, GHSA-32PM-63J6-22QC
Products
Emote Interactive:Remote Mouse Server 0 ≤4.110
Sources
euvd EUVD-2022-42745

Description

Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.

References