CVE-2022-23334
Critical · CVSS 9.8Ip-label Newtest — Improper Signature Verification / Privilege Escalation via Binary Replacement
- CVSS
- 9.8
- nvd
- EPSS
- 0.53%
- 41th pct
- KEV
- No
- Class
- other
- CWE-347, CWE-347
Description
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
Search profile — drives PoC discovery
Symbols NEWTESTREMOTEMANAGER.EXERobot applicationNewtestEkaraIp-label
Keywords CVE-2022-23334Ip-label NewtestNEWTESTREMOTEMANAGER.EXEweak signature checkbinary replacementprivilege escalationEkara NewtestON-X Security AdvisoryCWE-347
Versions: before v8.5R0
References
- https://www.on-x.com/wp-content/uploads/2023/01/ON-X-Security-Advisory-Ip-label-Ekara-Newtest-CVE-2022-23334.pdf
- http://ip-label.com
- http://newtest.com
- https://www.on-x.com/wp-content/uploads/2023/01/ON-X-Security-Advisory-Ip-label-Ekara-Newtest-CVE-2022-23334.pdf
- https://www.on-x.com/wp-content/uploads/2023/01/ON-X-Security-Advisory-Ip-label-Ekara-Newtest-CVE-2022-23334.pdf
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z