Lucene search

K
cveMitreCVE-2022-29730
HistoryJun 02, 2022 - 2:15 p.m.

CVE-2022-29730

2022-06-0214:15:50
CWE-798
mitre
web.nvd.nist.gov
55
2
cve-2022-29730
usr iot
4g lte
industrial
cellular
vpn router
v1.0.36
hardcoded credentials

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.003

Percentile

69.9%

USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.

Affected configurations

Nvd
Node
usrusr-g808_firmwareMatch1.0.36
AND
usrusr-g808Match-
Node
usrusr-g807_firmwareMatch1.0.36
AND
usrusr-g807Match-
Node
usrusr-g806_firmwareMatch1.0.36
AND
usrusr-g806Match-
Node
usrusr-g800v2_firmwareMatch1.0.36
AND
usrusr-g800v2Match-
Node
usrusr-lg220-l_firmwareMatch1.2.7
AND
usrusr-lg220-lMatch-
VendorProductVersionCPE
usrusr-g808_firmware1.0.36cpe:2.3:o:usr:usr-g808_firmware:1.0.36:*:*:*:*:*:*:*
usrusr-g808-cpe:2.3:h:usr:usr-g808:-:*:*:*:*:*:*:*
usrusr-g807_firmware1.0.36cpe:2.3:o:usr:usr-g807_firmware:1.0.36:*:*:*:*:*:*:*
usrusr-g807-cpe:2.3:h:usr:usr-g807:-:*:*:*:*:*:*:*
usrusr-g806_firmware1.0.36cpe:2.3:o:usr:usr-g806_firmware:1.0.36:*:*:*:*:*:*:*
usrusr-g806-cpe:2.3:h:usr:usr-g806:-:*:*:*:*:*:*:*
usrusr-g800v2_firmware1.0.36cpe:2.3:o:usr:usr-g800v2_firmware:1.0.36:*:*:*:*:*:*:*
usrusr-g800v2-cpe:2.3:h:usr:usr-g800v2:-:*:*:*:*:*:*:*
usrusr-lg220-l_firmware1.2.7cpe:2.3:o:usr:usr-lg220-l_firmware:1.2.7:*:*:*:*:*:*:*
usrusr-lg220-l-cpe:2.3:h:usr:usr-lg220-l:-:*:*:*:*:*:*:*

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.003

Percentile

69.9%

Related for CVE-2022-29730