CRITICAL · 9.8

CVE-2022-28814

Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arb...

Vulnerability Description

Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GavazziautomationCpy Car Park Server< 2.8.3
GavazziautomationUwp 3.0 Monitoring Gateway And Controller Firmware< 8.5.0.3
GavazziautomationUwp 3.0 Monitoring Gateway And Controller-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-28814?

CVE-2022-28814 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arb...

How severe is CVE-2022-28814?

CVE-2022-28814 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-28814?

Check the references section above for vendor advisories and patch information. Affected products include: Gavazziautomation Cpy Car Park Server, Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller Firmware, Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller.