HIGH · 7.2

CVE-2022-22525

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the bac...

Vulnerability Description

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GavazziautomationCpy Car Park Server< 2.8.3
GavazziautomationUwp 3.0 Monitoring Gateway And Controller Firmware< 8.5.0.3
GavazziautomationUwp 3.0 Monitoring Gateway And Controller-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-22525?

CVE-2022-22525 is a vulnerability with a CVSS score of 7.2 (HIGH). In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the bac...

How severe is CVE-2022-22525?

CVE-2022-22525 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-22525?

Check the references section above for vendor advisories and patch information. Affected products include: Gavazziautomation Cpy Car Park Server, Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller Firmware, Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller.