CVE-2022-47891

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
03/10/2023
Last modified:
04/10/2023

Description

All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:riello-ups:netman_204_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*