CVE-2022-2757

CVSS V2 None CVSS V3 None
Description
Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an attacker viewing and modifying the application settings without authenticating by accessing a specific uniform resource locator (URL) on the webserver.
Overview
  • CVE ID
  • CVE-2022-2757
  • Assigner
  • ics-cert@hq.dhs.gov
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-13T22:15:10
  • Last Modified Date
  • 2022-12-16T17:18:21
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:kingspan:tms300_cs_firmware:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:kingspan:tms300_cs:*:*:*:*:*:*:*:* 0 OR
References
History
Created Old Value New Value Data Type Notes
2022-12-13 23:14:13 Added to TrackCVE
2022-12-14 14:15:19 2022-12-13T22:15:10.007 2022-12-13T22:15:10 CVE Published Date updated
2022-12-14 14:15:19 2022-12-14T14:09:58 CVE Modified Date updated
2022-12-14 14:15:19 Received Awaiting Analysis Vulnerability Status updated
2022-12-18 04:35:26 2022-12-16T17:18:21 CVE Modified Date updated
2022-12-18 04:35:26 Awaiting Analysis Analyzed Vulnerability Status updated
2022-12-18 04:35:29 CWE-287 Weakness Enumeration new
2022-12-18 04:35:36 CPE Information updated