PT-2022-26874 · Ip Com · Ip-Com Ew9

Published

2022-10-27

·

Updated

2023-08-08

·

CVE-2022-43366

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IP-COM EW9 version 15.11.0.14(9732)
Description The issue allows unauthenticated attackers to access sensitive information. This is achieved via several interfaces, including "checkLoginUser", "ate", "telnet", "version", "setDebugCfg", and "boot".
Recommendations For IP-COM EW9 version 15.11.0.14(9732), consider restricting access to the mentioned interfaces as a temporary workaround until a patch is available. Avoid using these interfaces until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2022-43366

Affected Products

Ip-Com Ew9