CVE-2022-22512

CVSS V2 None CVSS V3 None
Description
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
Overview
  • CVE ID
  • CVE-2022-22512
  • Assigner
  • info@cert.vde.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-23T06:15:12
  • Last Modified Date
  • 2023-03-27T16:14:58
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:varta:element_backup_firmware:*:*:*:*:*:*:*:* 1 OR f21000400
cpe:2.3:h:varta:element_backup:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:varta:element_s1_firmware:*:*:*:*:*:*:*:* 1 OR 2e.3.8.0
cpe:2.3:h:varta:element_s1:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:varta:element_s2_firmware:*:*:*:*:*:*:*:* 1 OR 2e.3.8.0
cpe:2.3:h:varta:element_s2:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:varta:element_s3_firmware:*:*:*:*:*:*:*:* 1 OR 2e.3.8.0
cpe:2.3:o:varta:element_s3_firmware:*:*:*:*:*:*:*:* 1 OR 2e.4.0.0 2e.4.4.0
cpe:2.3:h:varta:element_s3:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:varta:element_s4_firmware:*:*:*:*:*:*:*:* 1 OR d21010400
cpe:2.3:h:varta:element_s4:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:varta:one_l_firmware:*:*:*:*:*:*:*:* 1 OR 2e.3.8.0
cpe:2.3:h:varta:one_l:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:varta:one_xl_firmware:*:*:*:*:*:*:*:* 1 OR 2e.3.8.0
cpe:2.3:h:varta:one_xl:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:varta:pulse_firmware:*:*:*:*:*:*:*:* 1 OR c21010800
cpe:2.3:h:varta:pulse:-:*:*:*:*:*:*:* 0 OR
References
Reference URL Reference Tags
https://cert.vde.com/en/advisories/VDE-2022-061/ Third Party Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 03:14:08 Added to TrackCVE
2023-04-17 03:14:10 Weakness Enumeration new