CVE-2022-3485 Vulnerability Details

  /     /     /  

CVE-2022-3485 Metadata Quick Info

CVE Published: 12/12/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: CERTVDE | Vendor: ifm | Product: moneo appliance
Status : PUBLISHED

CVE-2022-3485 Description

In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.

Metrics

CVSS Version: 3.1 | Base Score: 9.8 CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-640
CWE Name: CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Source: ifm

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-166
CAPEC Description: CAPEC-166 Force the System to Reset Values


Source: NVD (National Vulnerability Database).