CVE-2022-2302
11.07.2022, 11:15
Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowledge of the password.Enginsight
Vendor | Product | Version |
---|---|---|
lenze | c520_firmware | 1.07.00.2757 ≤ 𝑥 < 01.08.01.3021 |
lenze | c550_firmware | 1.07.00.2757 ≤ 𝑥 < 01.08.01.3021 |
lenze | c750_firmware | 1.07.00.2757 ≤ 𝑥 < 01.08.01.3021 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-304 - Missing Critical Step in AuthenticationThe software implements an authentication technique, but it skips a step that weakens the technique.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.