Vulnerability · NVD
CVE-2022-32550
MEDIUM 4.8
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service.
Attack vector : Network
No privileges required
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.51%
exploit very unlikely
percentile 40.6%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (8)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| 1password |
1password Android
|
Android | ≥7.0 <7.9.3 | cpe:2.3:a:1password:1password:*:*:*:*:*:android:*:* |
| 1password |
1password macOS
|
macOS | ≥7.0 <7.9.5 | cpe:2.3:a:1password:1password:*:*:*:*:*:macos:*:* |
| 1password |
1password iOS
|
iOS | ≥7.0 <7.9.6 | cpe:2.3:a:1password:1password:*:*:*:*:*:iphone_os:*:* |
| 1password |
1password Windows
|
Windows | ≥7.0 <7.9.829 | cpe:2.3:a:1password:1password:*:*:*:*:*:windows:*:* |
| 1password |
1password macOS
|
macOS | ≥8.0 <8.7.1 | cpe:2.3:a:1password:1password:*:*:*:*:*:macos:*:* |
| 1password |
1password Windows
|
Windows | ≥8.0 <8.7.1 | cpe:2.3:a:1password:1password:*:*:*:*:*:windows:*:* |
| 1password |
1password iOS
|
iOS | ≥8.0 <8.8.0-94 | cpe:2.3:a:1password:1password:*:*:*:*:*:iphone_os:*:* |
| 1password |
1password Android
|
Android | ≥8.0 <8.8.0-104 | cpe:2.3:a:1password:1password:*:*:*:*:*:android:*:* |