← Back

CVE-2022-22525

nvd nist
Published: Sep 28, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: info@cert.vde.com (Secondary)

Description

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function

Affected (4)

Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.8.3
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.5.0.3
Running on/withPlatform Versions
Gavazziautomation
Uwp 3.0 Monitoring Gateway And Controller
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.5.0.3
Running on/withPlatform Versions
Gavazziautomation
Uwp 3.0 Monitoring Gateway And Controller
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.5.0.3
Running on/withPlatform Versions
Gavazziautomation
Uwp 3.0 Monitoring Gateway And Controller
All versions

References (2)

Source: info@cert.vde.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.