« Volver al listado

CVE-2022-28816

Estado: ModificadaMedia (6.1)—

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-28816",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-28816",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-20T20:36:37.829229Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "Carlo Gavazzi",
          "product": "UWP 3.0 Monitoring Gateway and Controller",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "lessThan": "8.5.0.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Carlo Gavazzi",
          "product": "UWP 3.0 Monitoring Gateway and Controller – Security Enhanced",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "lessThan": "8.5.0.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Carlo Gavazzi",
          "product": "UWP 3.0 Monitoring Gateway and Controller – EDP version",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "lessThan": "8.5.0.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Carlo Gavazzi",
          "product": "CPY Car Park Server",
          "versions": [
            {
              "status": "affected",
              "version": "2",
              "lessThan": "2.8.3",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-28T14:15:10.743",
  "references": [
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service."
    },
    {
      "lang": "es",
      "value": "En Carlo Gavazzi UWP versión 3.0 en múltiples versiones y CPY Car Park Server en versión 2.8.3, el Proxy Sentilo es propenso a un ataque de tipo XSS reflejado que solo afecta al servicio Sentilo"
    }
  ],
  "lastModified": "2026-06-17T04:39:07.690",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gavazziautomation:cpy_car_park_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E670508-7A94-4A01-9C2B-51E82D5A861F",
              "versionEndExcluding": "2.8.3"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14B2D9AB-2D19-4AD6-A049-CDB6814CC8D0",
              "versionEndExcluding": "8.5.0.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "90DBF492-5F3A-4F53-ACFC-59F89470D632"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:edp:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BFC1445-995C-44F7-BE85-E0C1D462573E",
              "versionEndExcluding": "8.5.0.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:edp:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C7900CB8-560F-4DD7-82B9-8226A8F5F5CC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:security_enhanced:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6584CB1-FA0B-468D-AA58-F2D2F33763AA",
              "versionEndExcluding": "8.5.0.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:security_enhanced:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B29F6465-3533-4B50-B436-4DC4E6F1B361"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}