CVE-2022-3485

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
12/12/2022
Last modified:
07/11/2023

Description

In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ifm:moneo_qha210_firmware:*:*:*:*:*:*:*:* 1.9.3 (including)
cpe:2.3:h:ifm:moneo_qha210:-:*:*:*:*:*:*:*
cpe:2.3:o:ifm:moneo_qha200_firmware:*:*:*:*:*:*:*:* 1.9.3 (including)
cpe:2.3:h:ifm:moneo_qha200:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools