CVE-2022-22525
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: info@cert.vde.com (Secondary)
Description
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.5.0.3 |
| Running on/with | Platform Versions |
|---|---|
Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.5.0.3 |
| Running on/with | Platform Versions |
|---|---|
Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.5.0.3 |
| Running on/with | Platform Versions |
|---|---|
Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.