CVE-2022-33174
Estado: ModificadaAlta (7.5)—
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 14%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-33174",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2022-06-13T18:15:10.230",
"references": [
{
"url": "https://gynvael.coldwind.pl/?lang=en&id=748",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://gynvael.coldwind.pl/?lang=en&id=748",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext."
},
{
"lang": "es",
"value": "Las unidades de distribución de energía que son ejecutadas con el firmware de Powertek (varias marcas) versiones anteriores a 3.30.30, permiten omitir la autorización remota en la interfaz web. Para explotar la vulnerabilidad, un atacante debe enviar un paquete HTTP a la interfaz de recuperación de datos (/cgi/get_param.cgi) con la cookie tmpToken configurada con una cadena vacía seguida de un punto y coma. Esto evita la comprobación de la autorización de la sesión activa. Esto puede ser usado para conseguir los valores de los campos protegidos sys.passwd y sys.su.name que contienen el nombre de usuario y la contraseña en texto sin cifrar"
}
],
"lastModified": "2026-06-17T04:48:32.647",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:powertekpdus:basic_pdu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24FD9B82-5D75-491E-9D64-19B673378568",
"versionEndExcluding": "3.30.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:powertekpdus:basic_pdu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "960D65C6-F07C-4B85-8381-E90AE84F1A3B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:powertekpdus:pm_pdu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8331ED3-08F5-4262-8F10-6ABE8394764D",
"versionEndExcluding": "3.30.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:powertekpdus:pm_pdu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BA48F31E-2ACD-4E3C-870E-726A38C04EB1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:powertekpdus:piml_pdu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5AABA79-C8D8-4C7F-8140-8B95E176CE3D",
"versionEndExcluding": "3.30.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:powertekpdus:piml_pdu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5BBF300E-47B2-47FF-91C9-B0EA4473C476"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:powertekpdus:smart_pim_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72E649EC-CCAC-4D52-9917-AF5F98D9A385",
"versionEndExcluding": "3.30.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:powertekpdus:smart_pim:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EF6DEFFC-E208-42AA-9A86-9BEC62A95362"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:powertekpdus:smart_pos_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89A6F4C3-CA16-4CE4-BBBC-B477A8CF58AC",
"versionEndExcluding": "3.30.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:powertekpdus:smart_pos:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "733D34C9-2249-4D5B-8CBC-C905B8FD0CF5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:powertekpdus:smart_pom_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B2899F7-848E-4115-A5CA-E8372538999D",
"versionEndExcluding": "3.30.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:powertekpdus:smart_pom:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BFEFC68A-5C05-4D12-9A53-AAC7E74C164B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:powertekpdus:smart_poms_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A783F76-C41A-4295-B2F6-E9BD9D5AC6B5",
"versionEndExcluding": "3.30.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:powertekpdus:smart_poms:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5C57A1A7-ED1B-46E5-A708-435FF8105DA7"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}