Vulnerability Description
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Varta | Element Backup Firmware | < f21000400 |
| Varta | Element Backup | - |
| Varta | Element S1 Firmware | < 2e.3.8.0 |
| Varta | Element S1 | - |
| Varta | Element S2 Firmware | < 2e.3.8.0 |
| Varta | Element S2 | - |
| Varta | Element S3 Firmware | < 2e.3.8.0 |
| Varta | Element S3 | - |
| Varta | Element S4 Firmware | < d21010400 |
| Varta | Element S4 | - |
| Varta | One L Firmware | < 2e.3.8.0 |
| Varta | One L | - |
| Varta | One Xl Firmware | < 2e.3.8.0 |
| Varta | One Xl | - |
| Varta | Pulse Firmware | < c21010800 |
| Varta | Pulse | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en/advisories/VDE-2022-061/Third Party Advisory
- https://cert.vde.com/en/advisories/VDE-2022-061/Third Party Advisory
FAQ
What is CVE-2022-22512?
CVE-2022-22512 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
How severe is CVE-2022-22512?
CVE-2022-22512 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-22512?
Check the references section above for vendor advisories and patch information. Affected products include: Varta Element Backup Firmware, Varta Element Backup, Varta Element S1 Firmware, Varta Element S1, Varta Element S2 Firmware.