9.8

CVE-2022-22512

VARTA: Multiple devices prone to hard-coded credentials

Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Varta ≫ Element Backup Firmware Version < f21000400
   Varta ≫ Element Backup Version -
Varta ≫ Element S1 Firmware Version < 2e.3.8.0
   Varta ≫ Element S1 Version -
Varta ≫ Element S2 Firmware Version < 2e.3.8.0
   Varta ≫ Element S2 Version -
Varta ≫ Element S3 Firmware Version < 2e.3.8.0
   Varta ≫ Element S3 Version -
Varta ≫ Element S3 Firmware Version >= 2e.4.0.0 < 2e.4.4.0
   Varta ≫ Element S3 Version -
Varta ≫ Element S4 Firmware Version < d21010400
   Varta ≫ Element S4 Version -
Varta ≫ One L Firmware Version < 2e.3.8.0
   Varta ≫ One L Version -
Varta ≫ One Xl Firmware Version < 2e.3.8.0
   Varta ≫ One Xl Version -
Varta ≫ Pulse Firmware Version < c21010800
   Varta ≫ Pulse Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.68% 0.473
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://cert.vde.com/en/advisories/VDE-2022-061/
Third Party Advisory