9.8

CVE-2022-22512

Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VartaElement Backup Firmware Version < f21000400
   VartaElement Backup Version-
VartaElement S1 Firmware Version < 2e.3.8.0
   VartaElement S1 Version-
VartaElement S2 Firmware Version < 2e.3.8.0
   VartaElement S2 Version-
VartaElement S3 Firmware Version < 2e.3.8.0
   VartaElement S3 Version-
VartaElement S3 Firmware Version >= 2e.4.0.0 < 2e.4.4.0
   VartaElement S3 Version-
VartaElement S4 Firmware Version < d21010400
   VartaElement S4 Version-
VartaOne L Firmware Version < 2e.3.8.0
   VartaOne L Version-
VartaOne Xl Firmware Version < 2e.3.8.0
   VartaOne Xl Version-
VartaPulse Firmware Version < c21010800
   VartaPulse Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.29
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.