CVE-2022-47037
HIGHDescription
Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.
Is your site exposed to CVE-2022-47037?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| siklu | tg_firmware |
| siklu | tg_lr_t280 |
| siklu | tg_mpl-261 |
| siklu | tg_n265 |
| siklu | tg_n366 |
| siklu | tg_n367 |
| siklu | tg_t260 |
| siklu | tg_t261 |
| siklu | tg_t265 |
References
Frequently Asked Questions
What is CVE-2022-47037? +
How severe is CVE-2022-47037? +
What products are affected by CVE-2022-47037? +
How do I check if I'm vulnerable to CVE-2022-47037? +
Related Vulnerabilities
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials …
Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes …
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token …
ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This …
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect …
Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability …