PT-2022-21739 · L2Blocker · L2Blocker
Published
2022-06-27
·
Updated
2022-07-07
·
CVE-2022-33202
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
L2Blocker(on-premise) versions 4.8.5 and earlier
L2Blocker(Cloud) versions 4.8.5 and earlier
Description
The issue allows an adjacent attacker to bypass authentication in the setup screen, potentially leading to unauthorized login, access to stored information, or device malfunction. This is achieved by using alternative paths or channels for the Sensor.
Recommendations
For L2Blocker(on-premise) versions 4.8.5 and earlier, update to a version later than 4.8.5 to resolve the issue.
For L2Blocker(Cloud) versions 4.8.5 and earlier, update to a version later than 4.8.5 to resolve the issue.
As a temporary workaround, consider restricting access to the setup screen to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
L2Blocker