Vulnerability Description
MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Malighting | Grandma2 Light Firmware | - |
| Malighting | Grandma2 Light | - |
Related Weaknesses (CWE)
References
- https://parzival.sh/posts/Pwning-a-Lighting-Console-in-a-Few-Minutes/ExploitThird Party Advisory
- https://www.malighting.com/product-archive/product/grandma2-light-120112/ProductVendor Advisory
- https://parzival.sh/posts/Pwning-a-Lighting-Console-in-a-Few-Minutes/ExploitThird Party Advisory
- https://www.malighting.com/product-archive/product/grandma2-light-120112/ProductVendor Advisory
FAQ
What is CVE-2022-30036?
CVE-2022-30036 is a vulnerability with a CVSS score of 8.8 (HIGH). MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is no...
How severe is CVE-2022-30036?
CVE-2022-30036 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30036?
Check the references section above for vendor advisories and patch information. Affected products include: Malighting Grandma2 Light Firmware, Malighting Grandma2 Light.