PT-2022-21724 · Unknown+1 · Power Distribution Units+1
Published
2022-06-13
·
Updated
2023-08-08
·
CVE-2022-33175
CVSS v3.1
9.8
Critical
| Vector | AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
Power Distribution Units running on Powertek firmware versions prior to 3.30.30
Description
The issue concerns an insecure permissions setting on the
user.token field, which is accessible through the "/cgi/get param.cgi" HTTP API endpoint. This allows disclosure of active session IDs of currently logged-in administrators. An attacker can reuse the session ID to impersonate the administrator, enabling them to read the cleartext password or reconfigure the device.Recommendations
For versions prior to 3.30.30, update to version 3.30.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/cgi/get param.cgi" API endpoint to minimize the risk of exploitation. Avoid using the
user.token field in the affected API endpoint until the issue is resolved.Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Power Distribution Units
Powertek