Vulnerability Description
All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Riello-Ups | Netman 204 Firmware | All versions |
| Riello-Ups | Netman 204 | - |
Related Weaknesses (CWE)
References
- https://www.incibe.es/incibe-cert/alerta-temprana/avisos-sci/multiples-vulnerabiThird Party Advisory
- https://www.incibe.es/incibe-cert/alerta-temprana/avisos-sci/multiples-vulnerabiThird Party Advisory
FAQ
What is CVE-2022-47891?
CVE-2022-47891 is a vulnerability with a CVSS score of 8.1 (HIGH). All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.
How severe is CVE-2022-47891?
CVE-2022-47891 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-47891?
Check the references section above for vendor advisories and patch information. Affected products include: Riello-Ups Netman 204 Firmware, Riello-Ups Netman 204.