CVE-2022-2052Improper Access Control in Werkzeugmaschinen SE + CO KG Oseon

Severity
9.8CRITICALNVD
EPSS
0.4%
top 41.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17

Description

Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

🔴Vulnerability Details

2
CVEList
TRUMPF TruTops default user accounts vulnerability2022-10-17
GHSA
GHSA-rx57-wv3q-7323: Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords2022-10-17
CVE-2022-2052 — Improper Access Control | cvebase