← Back

CVE-2022-28815

nvd nist
Published: Sep 28, 2022Modified: Nov 21, 2024

JSON object

Loading...
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.2 / Impact: 1.4
Source: NVD (Secondary)

Description

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was discovered to contain a SQL injection vulnerability allowing an attacker to query other tables of the Sentilo service.

Affected (4)

Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.8.3
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.5.0.3
Running on/withPlatform Versions
Gavazziautomation
Uwp 3.0 Monitoring Gateway And Controller
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.5.0.3
Running on/withPlatform Versions
Gavazziautomation
Uwp 3.0 Monitoring Gateway And Controller
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.5.0.3
Running on/withPlatform Versions
Gavazziautomation
Uwp 3.0 Monitoring Gateway And Controller
All versions

References (2)

Source: info@cert.vde.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.