CVE-2022-1039 Information
Jun 07, 2022
cve
Description
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet the former of which is by default enabled on trusted interfaces. While the SSH service does not support root login a user logging in using either of the other Linux accounts may elevate to root access using the su command if they have access to the associated password.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.cisa.gov/uscert/ics/advisories/icsa-22-104-03
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: