TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2022-33174

CRITICAL
9.8

Beschreibung

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht6/13/2022
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

powertekpdus:basic_pdupowertekpdus:basic_pdu_firmwarepowertekpdus:piml_pdupowertekpdus:piml_pdu_firmwarepowertekpdus:pm_pdupowertekpdus:pm_pdu_firmwarepowertekpdus:smart_pimpowertekpdus:smart_pim_firmwarepowertekpdus:smart_pompowertekpdus:smart_pom_firmwarepowertekpdus:smart_pomspowertekpdus:smart_poms_firmwarepowertekpdus:smart_pospowertekpdus:smart_pos_firmware

Schwachen (CWE)

CWE-863

Referenzen

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.