CVE-2022-28816
Estado: ModificadaMedia (6.1)—
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.43%
- Percentil entre todas las CVEs puntuadas: 35
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-79
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-28816",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-28816",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-20T20:36:37.829229Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "Carlo Gavazzi",
"product": "UWP 3.0 Monitoring Gateway and Controller",
"versions": [
{
"status": "affected",
"version": "8",
"lessThan": "8.5.0.3",
"versionType": "custom"
}
]
},
{
"vendor": "Carlo Gavazzi",
"product": "UWP 3.0 Monitoring Gateway and Controller – Security Enhanced",
"versions": [
{
"status": "affected",
"version": "8",
"lessThan": "8.5.0.3",
"versionType": "custom"
}
]
},
{
"vendor": "Carlo Gavazzi",
"product": "UWP 3.0 Monitoring Gateway and Controller – EDP version",
"versions": [
{
"status": "affected",
"version": "8",
"lessThan": "8.5.0.3",
"versionType": "custom"
}
]
},
{
"vendor": "Carlo Gavazzi",
"product": "CPY Car Park Server",
"versions": [
{
"status": "affected",
"version": "2",
"lessThan": "2.8.3",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-09-28T14:15:10.743",
"references": [
{
"url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
"tags": [
"Third Party Advisory"
],
"source": "info@cert.vde.com"
},
{
"url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service."
},
{
"lang": "es",
"value": "En Carlo Gavazzi UWP versión 3.0 en múltiples versiones y CPY Car Park Server en versión 2.8.3, el Proxy Sentilo es propenso a un ataque de tipo XSS reflejado que solo afecta al servicio Sentilo"
}
],
"lastModified": "2026-06-17T04:39:07.690",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gavazziautomation:cpy_car_park_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E670508-7A94-4A01-9C2B-51E82D5A861F",
"versionEndExcluding": "2.8.3"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14B2D9AB-2D19-4AD6-A049-CDB6814CC8D0",
"versionEndExcluding": "8.5.0.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "90DBF492-5F3A-4F53-ACFC-59F89470D632"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:edp:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BFC1445-995C-44F7-BE85-E0C1D462573E",
"versionEndExcluding": "8.5.0.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:edp:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C7900CB8-560F-4DD7-82B9-8226A8F5F5CC"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:security_enhanced:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6584CB1-FA0B-468D-AA58-F2D2F33763AA",
"versionEndExcluding": "8.5.0.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:security_enhanced:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B29F6465-3533-4B50-B436-4DC4E6F1B361"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "info@cert.vde.com"
}