CVE-2022-47558
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or modify existing users, modify configuration files, install rootkits or backdoors.
Affected (2)
Products: Ormazabal: Ekorrci Firmware, Ekorccp Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 601j |
| Running on/with | Platform Versions |
|---|---|
Ormazabal Ekorrci | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 601j |
| Running on/with | Platform Versions |
|---|---|
Ormazabal Ekorccp | All versions |
Related CWEs
References (2)
Source: cve-coordination@incibe.es
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.