TROYANOSYVIRUS
Voltar para CVEs

CVE-2022-47558

CRITICAL
9.4

Descricao

Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or modify existing users, modify configuration files, install rootkits or backdoors.

Detalhes CVE

Pontuacao CVSS v3.19.4
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado9/19/2023
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0

Produtos afetados

ormazabal:ekorccpormazabal:ekorccp_firmwareormazabal:ekorrciormazabal:ekorrci_firmware

Fraquezas (CWE)

CWE-284CWE-798

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.