9.8
CVE-2022-22522
- EPSS 0.9%
- Veröffentlicht 28.09.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:46:57
- Erkennungen
Hard-coded credentials in Carlo Gavazzi UWP3.0 allows for authentication bypass and full control of the device
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gavazziautomation ≫ Cpy Car Park Server Version < 2.8.3
Gavazziautomation ≫ Uwp 3.0 Monitoring Gateway And Controller Firmware Version < 8.5.0.3
Gavazziautomation ≫ Uwp 3.0 Monitoring Gateway And Controller Firmware Edition edp Version < 8.5.0.3
Gavazziautomation ≫ Uwp 3.0 Monitoring Gateway And Controller Firmware Edition security_enhanced Version < 8.5.0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.9% | 0.562 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
https://cert.vde.com/en/advisories/VDE-2022-029/