PT-2022-21724 · Unknown+1 · Power Distribution Units+1

Published

2022-06-13

·

Updated

2023-08-08

·

CVE-2022-33175

CVSS v3.1

9.8

Critical

VectorAC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions Power Distribution Units running on Powertek firmware versions prior to 3.30.30
Description The issue concerns an insecure permissions setting on the user.token field, which is accessible through the "/cgi/get param.cgi" HTTP API endpoint. This allows disclosure of active session IDs of currently logged-in administrators. An attacker can reuse the session ID to impersonate the administrator, enabling them to read the cleartext password or reconfigure the device.
Recommendations For versions prior to 3.30.30, update to version 3.30.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/cgi/get param.cgi" API endpoint to minimize the risk of exploitation. Avoid using the user.token field in the affected API endpoint until the issue is resolved.

Exploit

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2022-33175

Affected Products

Power Distribution Units
Powertek