« Volver al listado

CVE-2022-22525

Estado: ModificadaAlta (7.2)—

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-22525",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-22525",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-21T14:36:46.092109Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "Carlo Gavazzi",
          "product": "UWP 3.0 Monitoring Gateway and Controller",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "lessThan": "8.5.0.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Carlo Gavazzi",
          "product": "UWP 3.0 Monitoring Gateway and Controller – Security Enhanced",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "lessThan": "8.5.0.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Carlo Gavazzi",
          "product": "UWP 3.0 Monitoring Gateway and Controller – EDP version",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "lessThan": "8.5.0.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Carlo Gavazzi",
          "product": "CPY Car Park Server",
          "versions": [
            {
              "status": "affected",
              "version": "2",
              "lessThan": "2.8.3",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-28T14:15:10.187",
  "references": [
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function"
    },
    {
      "lang": "es",
      "value": "En Carlo Gavazzi UWP versión 3.0 en múltiples versiones y CPY Car Park Server en versión 2.8.3, un atacante remoto con derechos de administrador podría ejecutar comandos arbitrarios debido a una falta de saneo de entrada en la función backup restore"
    }
  ],
  "lastModified": "2026-06-17T04:28:31.990",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gavazziautomation:cpy_car_park_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E670508-7A94-4A01-9C2B-51E82D5A861F",
              "versionEndExcluding": "2.8.3"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14B2D9AB-2D19-4AD6-A049-CDB6814CC8D0",
              "versionEndExcluding": "8.5.0.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "90DBF492-5F3A-4F53-ACFC-59F89470D632"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:edp:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BFC1445-995C-44F7-BE85-E0C1D462573E",
              "versionEndExcluding": "8.5.0.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:edp:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C7900CB8-560F-4DD7-82B9-8226A8F5F5CC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:security_enhanced:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6584CB1-FA0B-468D-AA58-F2D2F33763AA",
              "versionEndExcluding": "8.5.0.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:security_enhanced:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B29F6465-3533-4B50-B436-4DC4E6F1B361"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}