CVE-2022-22525
Estado: ModificadaAlta (7.2)—
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.17%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-22525",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-22525",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-21T14:36:46.092109Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "Carlo Gavazzi",
"product": "UWP 3.0 Monitoring Gateway and Controller",
"versions": [
{
"status": "affected",
"version": "8",
"lessThan": "8.5.0.3",
"versionType": "custom"
}
]
},
{
"vendor": "Carlo Gavazzi",
"product": "UWP 3.0 Monitoring Gateway and Controller – Security Enhanced",
"versions": [
{
"status": "affected",
"version": "8",
"lessThan": "8.5.0.3",
"versionType": "custom"
}
]
},
{
"vendor": "Carlo Gavazzi",
"product": "UWP 3.0 Monitoring Gateway and Controller – EDP version",
"versions": [
{
"status": "affected",
"version": "8",
"lessThan": "8.5.0.3",
"versionType": "custom"
}
]
},
{
"vendor": "Carlo Gavazzi",
"product": "CPY Car Park Server",
"versions": [
{
"status": "affected",
"version": "2",
"lessThan": "2.8.3",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-09-28T14:15:10.187",
"references": [
{
"url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
"tags": [
"Third Party Advisory"
],
"source": "info@cert.vde.com"
},
{
"url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function"
},
{
"lang": "es",
"value": "En Carlo Gavazzi UWP versión 3.0 en múltiples versiones y CPY Car Park Server en versión 2.8.3, un atacante remoto con derechos de administrador podría ejecutar comandos arbitrarios debido a una falta de saneo de entrada en la función backup restore"
}
],
"lastModified": "2026-06-17T04:28:31.990",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gavazziautomation:cpy_car_park_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E670508-7A94-4A01-9C2B-51E82D5A861F",
"versionEndExcluding": "2.8.3"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14B2D9AB-2D19-4AD6-A049-CDB6814CC8D0",
"versionEndExcluding": "8.5.0.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "90DBF492-5F3A-4F53-ACFC-59F89470D632"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:edp:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BFC1445-995C-44F7-BE85-E0C1D462573E",
"versionEndExcluding": "8.5.0.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:edp:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C7900CB8-560F-4DD7-82B9-8226A8F5F5CC"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:security_enhanced:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6584CB1-FA0B-468D-AA58-F2D2F33763AA",
"versionEndExcluding": "8.5.0.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:security_enhanced:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B29F6465-3533-4B50-B436-4DC4E6F1B361"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "info@cert.vde.com"
}