CVE-2022-2757
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
13/12/2022
Last modified:
07/11/2023
Description
<br />
<br />
<br />
Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an attacker viewing and modifying the application settings without authenticating by accessing a specific uniform resource locator (URL) on the webserver.<br />
<br />
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:kingspan:tms300_cs_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:kingspan:tms300_cs:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



