CVE-2022-2302

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
11/07/2022
Last modified:
18/07/2022

Description

Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowledge of the password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenze:c520_firmware:*:*:*:*:*:*:*:* 1.07.00.2757 (including) 01.08.01.3021 (excluding)
cpe:2.3:h:lenze:c520:-:*:*:*:*:*:*:*
cpe:2.3:o:lenze:c550_firmware:*:*:*:*:*:*:*:* 1.07.00.2757 (including) 01.08.01.3021 (excluding)
cpe:2.3:h:lenze:c550:-:*:*:*:*:*:*:*
cpe:2.3:o:lenze:c750_firmware:*:*:*:*:*:*:*:* 1.07.00.2757 (including) 01.08.01.3021 (excluding)
cpe:2.3:h:lenze:c750:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools