peter bassill · operator
$ cve CVE-2022-33174 JSON

CVE-2022-33174

9.8
CRITICAL · CVSS 3.1 · EPSS 14.1% (pctl 96)

Patch early

EPSS 14.1% — above the 10% action threshold.

Description

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS14.12% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-863
On CISA KEVno
Public exploitnone known
Published2022-06-13
Last modified2026-06-17

Affected (14)

VendorProduct
powertekpdusbasic pdu
powertekpdusbasic pdu firmware
powertekpduspiml pdu
powertekpduspiml pdu firmware
powertekpduspm pdu
powertekpduspm pdu firmware
powertekpdussmart pim
powertekpdussmart pim firmware
powertekpdussmart pom
powertekpdussmart pom firmware
powertekpdussmart poms
powertekpdussmart poms firmware
powertekpdussmart pos
powertekpdussmart pos firmware

References

→ the Explorer  ·  watch your stack  ·  NVD