Vulnerability Details CVE-2022-2105
Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.7%
CVSS Severity
CVSS v3 Score 9.4
CVSS v2 Score 6.4
Products affected by CVE-2022-2105
-
cpe:2.3:h:secheron:sepcos_control_and_protection_relay:-
-
cpe:2.3:o:secheron:sepcos_control_and_protection_relay_firmware:1.23.0
-
cpe:2.3:o:secheron:sepcos_control_and_protection_relay_firmware:1.24.0
-
cpe:2.3:o:secheron:sepcos_control_and_protection_relay_firmware:1.25.0