« Volver al listado

CVE-2022-28814

Estado: ModificadaCrítica (9.8)—

Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-28814",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-28814",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-20T20:35:33.774091Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "Carlo Gavazzi",
          "product": "UWP 3.0 Monitoring Gateway and Controller",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "lessThan": "8.5.0.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Carlo Gavazzi",
          "product": "UWP 3.0 Monitoring Gateway and Controller – Security Enhanced",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "lessThan": "8.5.0.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Carlo Gavazzi",
          "product": "UWP 3.0 Monitoring Gateway and Controller – EDP version",
          "versions": [
            {
              "status": "affected",
              "version": "8",
              "lessThan": "8.5.0.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Carlo Gavazzi",
          "product": "CPY Car Park Server",
          "versions": [
            {
              "status": "affected",
              "version": "2",
              "lessThan": "2.8.3",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-28T14:15:10.587",
  "references": [
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2022-029/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-23"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device."
    },
    {
      "lang": "es",
      "value": "En Carlo Gavazzi UWP versión 3.0 en múltiples versiones y en CPY Car Park Server en versión 2.8.3, Se ha detectado que era susceptible a una vulnerabilidad de salto de ruta relativo que permite a atacantes remotos leer archivos arbitrarios y obtener el control total del dispositivo"
    }
  ],
  "lastModified": "2026-06-17T04:39:07.433",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gavazziautomation:cpy_car_park_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E670508-7A94-4A01-9C2B-51E82D5A861F",
              "versionEndExcluding": "2.8.3"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14B2D9AB-2D19-4AD6-A049-CDB6814CC8D0",
              "versionEndExcluding": "8.5.0.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "90DBF492-5F3A-4F53-ACFC-59F89470D632"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:edp:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BFC1445-995C-44F7-BE85-E0C1D462573E",
              "versionEndExcluding": "8.5.0.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:edp:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C7900CB8-560F-4DD7-82B9-8226A8F5F5CC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:security_enhanced:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6584CB1-FA0B-468D-AA58-F2D2F33763AA",
              "versionEndExcluding": "8.5.0.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:security_enhanced:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B29F6465-3533-4B50-B436-4DC4E6F1B361"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}