CVE-2022-22512

Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:varta:element_backup_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:element_backup:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:varta:element_s1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:element_s1:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:varta:element_s2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:element_s2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:varta:element_s3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:varta:element_s3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:element_s3:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:varta:element_s4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:element_s4:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:varta:one_l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:one_l:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:varta:one_xl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:one_xl:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:varta:pulse_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:pulse:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:46

Type Values Removed Values Added
References () https://cert.vde.com/en/advisories/VDE-2022-061/ - Third Party Advisory () https://cert.vde.com/en/advisories/VDE-2022-061/ - Third Party Advisory

27 Mar 2023, 16:14

Type Values Removed Values Added
References (MISC) https://cert.vde.com/en/advisories/VDE-2022-061/ - (MISC) https://cert.vde.com/en/advisories/VDE-2022-061/ - Third Party Advisory
CVSS v2 : unknown
v3 : 9.1
v2 : unknown
v3 : 9.8
CPE cpe:2.3:h:varta:element_s1:-:*:*:*:*:*:*:*
cpe:2.3:h:varta:one_xl:-:*:*:*:*:*:*:*
cpe:2.3:o:varta:element_s4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:element_s2:-:*:*:*:*:*:*:*
cpe:2.3:o:varta:one_l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:varta:element_s1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:varta:element_s3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:varta:element_backup_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:varta:pulse_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:varta:pulse:-:*:*:*:*:*:*:*
cpe:2.3:h:varta:one_l:-:*:*:*:*:*:*:*
cpe:2.3:h:varta:element_backup:-:*:*:*:*:*:*:*
cpe:2.3:h:varta:element_s3:-:*:*:*:*:*:*:*
cpe:2.3:h:varta:element_s4:-:*:*:*:*:*:*:*
cpe:2.3:o:varta:one_xl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:varta:element_s2_firmware:*:*:*:*:*:*:*:*
First Time Varta element S2
Varta pulse Firmware
Varta element S2 Firmware
Varta one Xl
Varta element S1
Varta
Varta one L Firmware
Varta element S3
Varta element S4 Firmware
Varta element S4
Varta pulse
Varta one Xl Firmware
Varta element Backup Firmware
Varta element S1 Firmware
Varta element S3 Firmware
Varta element Backup
Varta one L

23 Mar 2023, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-23 06:15

Updated : 2024-11-21 06:46


NVD link : CVE-2022-22512

Mitre link : CVE-2022-22512

CVE.ORG link : CVE-2022-22512


JSON object : View

Products Affected

varta

  • one_xl
  • element_s3_firmware
  • pulse_firmware
  • element_s2
  • pulse
  • element_s2_firmware
  • element_s1_firmware
  • one_l
  • element_s4_firmware
  • one_xl_firmware
  • element_s1
  • element_s3
  • element_backup_firmware
  • element_s4
  • one_l_firmware
  • element_backup
CWE
CWE-798

Use of Hard-coded Credentials