CVE-2022-27179 Vulnerability Details

  /     /     /  

CVE-2022-27179 Metadata Quick Info

CVE Published: 20/04/2022 | CVE Updated: 17/09/2024 | CVE Year: 2022
Source: icscert | Vendor: Red Lion | Product: DA50N
Status : PUBLISHED

CVE-2022-27179 Description

A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised.

Metrics

CVSS Version: 3.1 | Base Score: 4.6 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* LOW
    Availability Impact (A)* LOW

Weakness Enumeration (CWE)

CWE-ID: CWE-522
CWE Name: CWE-522 Insufficiently Protected Credentials
Source: Red Lion

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).