CVE Feed

    Dashboard / CVE / CVE-2022-33175

    CVE-2022-33175

    Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device.

    Published:Jun 13, 2022
    Last Modified:Nov 21, 2024
    EPS:Jun 13, 2022
    EPSS Score:0.00526
    CVSS Score:9.8

    Affected Products

    Vendor
    Powertekpdus
    Product
    Basic Pdu
    Vendor
    Powertekpdus
    Product
    Basic Pdu Firmware
    Vendor
    Powertekpdus
    Product
    Piml Pdu
    Vendor
    Powertekpdus
    Product
    Piml Pdu Firmware
    Vendor
    Powertekpdus
    Product
    Pm Pdu
    Vendor
    Powertekpdus
    Product
    Pm Pdu Firmware
    Vendor
    Powertekpdus
    Product
    Smart Pim
    Vendor
    Powertekpdus
    Product
    Smart Pim Firmware
    Vendor
    Powertekpdus
    Product
    Smart Pom
    Vendor
    Powertekpdus
    Product
    Smart Pom Firmware
    Vendor
    Powertekpdus
    Product
    Smart Poms
    Vendor
    Powertekpdus
    Product
    Smart Poms Firmware
    Vendor
    Powertekpdus
    Product
    Smart Pos
    Vendor
    Powertekpdus
    Product
    Smart Pos Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High