CVE Feed

    Dashboard / CVE / CVE-2022-33174

    CVE-2022-33174

    Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.

    Published:Jun 13, 2022
    Last Modified:Nov 21, 2024
    EPS:Jun 13, 2022
    EPSS Score:0.81715
    CVSS Score:9.8

    Affected Products

    Vendor
    Powertekpdus
    Product
    Basic Pdu
    Vendor
    Powertekpdus
    Product
    Basic Pdu Firmware
    Vendor
    Powertekpdus
    Product
    Piml Pdu
    Vendor
    Powertekpdus
    Product
    Piml Pdu Firmware
    Vendor
    Powertekpdus
    Product
    Pm Pdu
    Vendor
    Powertekpdus
    Product
    Pm Pdu Firmware
    Vendor
    Powertekpdus
    Product
    Smart Pim
    Vendor
    Powertekpdus
    Product
    Smart Pim Firmware
    Vendor
    Powertekpdus
    Product
    Smart Pom
    Vendor
    Powertekpdus
    Product
    Smart Pom Firmware
    Vendor
    Powertekpdus
    Product
    Smart Poms
    Vendor
    Powertekpdus
    Product
    Smart Poms Firmware
    Vendor
    Powertekpdus
    Product
    Smart Pos
    Vendor
    Powertekpdus
    Product
    Smart Pos Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High