CVE-2022-2105
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2022
Last modified:
06/07/2022
Description
Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:secheron:sepcos_control_and_protection_relay_firmware:*:*:*:*:*:*:*:* | 1.23.0 (including) | 1.23.21 (excluding) |
| cpe:2.3:o:secheron:sepcos_control_and_protection_relay_firmware:*:*:*:*:*:*:*:* | 1.24.0 (including) | 1.24.8 (excluding) |
| cpe:2.3:o:secheron:sepcos_control_and_protection_relay_firmware:*:*:*:*:*:*:*:* | 1.25.0 (including) | 1.25.3 (excluding) |
| cpe:2.3:h:secheron:sepcos_control_and_protection_relay:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



