CVE-2022-47554

Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml files, including .xml files containing credentials, without being authenticated within the web server.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ormazabal:ekorrci_firmware:601j:*:*:*:*:*:*:*
cpe:2.3:h:ormazabal:ekorrci:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ormazabal:ekorccp_firmware:601j:*:*:*:*:*:*:*
cpe:2.3:h:ormazabal:ekorccp:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:56

Type Values Removed Values Added
Summary ** UNSUPPPORTED WHEN ASSIGNED ** Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml files, including .xml files containing credentials, without being authenticated within the web server. Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml files, including .xml files containing credentials, without being authenticated within the web server.

21 Sep 2023, 19:44

Type Values Removed Values Added
CPE cpe:2.3:h:ormazabal:ekorrci:-:*:*:*:*:*:*:*
cpe:2.3:h:ormazabal:ekorccp:-:*:*:*:*:*:*:*
cpe:2.3:o:ormazabal:ekorccp_firmware:601j:*:*:*:*:*:*:*
cpe:2.3:o:ormazabal:ekorrci_firmware:601j:*:*:*:*:*:*:*
References (MISC) https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ormazabal-products - (MISC) https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ormazabal-products - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE NVD-CWE-noinfo
First Time Ormazabal ekorccp Firmware
Ormazabal ekorrci
Ormazabal ekorrci Firmware
Ormazabal ekorccp
Ormazabal

19 Sep 2023, 13:23

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-19 13:16

Updated : 2024-05-14 11:49


NVD link : CVE-2022-47554

Mitre link : CVE-2022-47554

CVE.ORG link : CVE-2022-47554


JSON object : View

Products Affected

ormazabal

  • ekorrci
  • ekorccp_firmware
  • ekorrci_firmware
  • ekorccp
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor