ZeroHour

CVE-2022-31765

CVSS 3.1
8.8 high
EPSS
<1%p59
Published
()
Modified
Description

Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.

Vendors
siemens
Products
6gk6108-4am00-2ba2 firmware, 6gk6108-4am00-2da2 firmware, 6gk5804-0ap00-2aa2 firmware, 6gk5812-1aa00-2aa2 firmware, 6gk5812-1ba00-2aa2 firmware, 6gk5816-1aa00-2aa2 firmware, 6gk5816-1ba00-2aa2 firmware, 6gk5826-2ab00-2ab2 firmware, 6gk5874-2aa00-2aa2 firmware, 6gk5874-3aa00-2aa2 firmware, 6gk5876-3aa02-2ba2 firmware, 6gk5876-3aa02-2ea2 firmware
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.