CVE-2022-3482718.11.2022, 23:15Carel Boss Mini 1.5.0 has Improper Access Control.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST9.9 CRITICALNETWORKLOWLOWCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HmitreCNA------CVEADP------CISA-ADPADP8.8 HIGHNETWORKLOWLOWCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HBase ScoreCVSS 3.xEPSS ScorePercentile: 22%VendorProductVersioncarelboss_mini_firmware1.5.0𝑥= Vulnerable software versionsKnown Exploits!https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0040/MNDT-2022-0040.mdhttps://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0040/MNDT-2022-0040.mdCommon Weakness EnumerationCWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.Referenceshttps://github.com/mandiant/Vulnerability-Disclosureshttps://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0040/MNDT-2022-0040.mdhttps://github.com/mandiant/Vulnerability-Disclosureshttps://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0040/MNDT-2022-0040.md