CVE-2022-47557 Vulnerability Details

  /     /     /  

CVE-2022-47557 Metadata Quick Info

CVE Published: 19/09/2023 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: INCIBE | Vendor: Ormazabal | Product: ekorCCP
Status : PUBLISHED

CVE-2022-47557 Description

Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located to decrypt the credentials of privileged users, and subsequently gain access to the system to perform malicious actions.

Metrics

CVSS Version: 3.1 | Base Score: 6.1 MEDIUM
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* LOW
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-916
CWE Name: CWE-916 Use of Password Hash With Insufficient Computational Effort
Source: Ormazabal

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).