Vulnerability Description
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included). This does not exist in SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solar-Log | Solar-Log 250 Firmware | < 4.2.8_117 |
| Solar-Log | Solar-Log 250 | - |
| Solar-Log | Solar-Log 300 Firmware | < 4.2.8_117 |
| Solar-Log | Solar-Log 300 | - |
| Solar-Log | Solar-Log 500 Firmware | < 4.2.8_117 |
| Solar-Log | Solar-Log 500 | - |
| Solar-Log | Solar-Log 800E Firmware | < 4.2.8_117 |
| Solar-Log | Solar-Log 800E | - |
| Solar-Log | Solar-Log 1000 Firmware | < 4.2.8_117 |
| Solar-Log | Solar-Log 1000 | - |
| Solar-Log | Solar-Log 1000 Pm\+ Firmware | < 4.2.8_117 |
| Solar-Log | Solar-Log 1000 Pm\+ | - |
| Solar-Log | Solar-Log 1200 Firmware | < 4.2.8_117 |
| Solar-Log | Solar-Log 1200 | - |
| Solar-Log | Solar-Log 2000 Firmware | < 4.2.8_117 |
| Solar-Log | Solar-Log 2000 | - |
| Solar-Log | Solar-Log 50 Firmware | < 4.2.8_117 |
| Solar-Log | Solar-Log 50 | - |
Related Weaknesses (CWE)
References
- https://www.solar-log.com/en/support/firmware-database-1Vendor Advisory
- https://www.swascan.com/security-advisory-solar-log/ExploitThird Party Advisory
- https://www.solar-log.com/en/support/firmware-database-1Vendor Advisory
- https://www.swascan.com/security-advisory-solar-log/ExploitThird Party Advisory
FAQ
What is CVE-2022-47767?
CVE-2022-47767 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up ...
How severe is CVE-2022-47767?
CVE-2022-47767 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-47767?
Check the references section above for vendor advisories and patch information. Affected products include: Solar-Log Solar-Log 250 Firmware, Solar-Log Solar-Log 250, Solar-Log Solar-Log 300 Firmware, Solar-Log Solar-Log 300, Solar-Log Solar-Log 500 Firmware.