← All CVEs

CVE-2022-33174

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.

9.8
CVSS
14.1%
EPSS (exploit prob.)
96th
EPSS percentile
2022-06-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-863

Affected products

VendorProductAffected versions
powertekpdusbasic_pdu_firmware< 3.30.30
powertekpdusbasic_pduall versions
powertekpduspm_pdu_firmware< 3.30.30
powertekpduspm_pduall versions
powertekpduspiml_pdu_firmware< 3.30.30
powertekpduspiml_pduall versions
powertekpdussmart_pim_firmware< 3.30.30
powertekpdussmart_pimall versions
powertekpdussmart_pos_firmware< 3.30.30
powertekpdussmart_posall versions
powertekpdussmart_pom_firmware< 3.30.30
powertekpdussmart_pomall versions
powertekpdussmart_poms_firmware< 3.30.30
powertekpdussmart_pomsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-33174