9.8

CVE-2022-1300

Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TrumpfTrutops Boost Version >= 13.01 <= 13.05
TrumpfTrutops Boost Version13.08.21
TrumpfTrutops Fab Version >= 22.01 <= 22.05
TrumpfTrutops Fab Version22.08.21
TrumpfTrutops Monitor Version >= 22.01 <= 22.05
TrumpfTrutops Monitor Version22.08.21
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.666
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
info@cert.vde.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.