CVE-2022-3010
HIGHDescription
The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| priva | top_control_suite |
References
Frequently Asked Questions
What is CVE-2022-3010? +
How severe is CVE-2022-3010? +
What products are affected by CVE-2022-3010? +
How do I check if I'm vulnerable to CVE-2022-3010? +
Related Vulnerabilities
Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs …
Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they …
Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a …
Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An …
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with …