Description
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.
Published: 2022-12-12
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-42857 In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.
History

Tue, 22 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Ifm Moneo Qha200 Moneo Qha200 Firmware Moneo Qha210 Moneo Qha210 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2025-04-22T17:52:53.648Z

Reserved: 2022-10-13T09:30:09.401Z

Link: CVE-2022-3485

cve-icon Vulnrichment

Updated: 2024-08-03T01:14:01.533Z

cve-icon NVD

Status : Modified

Published: 2022-12-12T12:15:10.697

Modified: 2024-11-21T07:19:37.930

Link: CVE-2022-3485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses