Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Carlo Gavazzi | UWP 3.0 Monitoring Gateway and Controller | 8 ~ 8.5.0.3 | - | |
| Carlo Gavazzi | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | 8 ~ 8.5.0.3 | - | |
| Carlo Gavazzi | UWP 3.0 Monitoring Gateway and Controller – EDP version | 8 ~ 8.5.0.3 | - | |
| Carlo Gavazzi | CPY Car Park Server | 2 ~ 2.8.3 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-22526 | 9.8 CRITICAL | Missing authentication for API in Carlo Gavazzi UWP 3.0 Car Park Server |
| CVE-2022-28811 | 9.8 CRITICAL | Possible command injection in Car Park Server in Carlo Gavazzi UWP3.0 |
| CVE-2022-28812 | 9.8 CRITICAL | Use of Hard-coded Credentials in UWP3.0 allows SuperUser authentication bypass in Car Park |
| CVE-2022-28814 | 9.8 CRITICAL | Path traversal in Carlo Gavazzi UWP 3.0 could lead to full device access |
| CVE-2022-22524 | 9.4 CRITICAL | SQL-injection in Carlo Gavazzi UWP 3.0 allows for full database access |
| CVE-2022-22523 | 7.5 HIGH | Carlo Gavazzi UWP 3.0 WebApp allows for authentication bypass |
| CVE-2022-28813 | 7.5 HIGH | SQL-injection in Car Park Server 3.0 allows for full database access. |
| CVE-2022-22525 | 7.2 HIGH | Command injection in restore function of Carlo Gavazzi UWP3.0 allows for command injection |
| CVE-2022-28816 | 6.1 MEDIUM | Reflected XSS in Carlo Gavazzi UWP 3.0 |
| CVE-2022-28815 | 2.7 LOW | SQL-Injection in Carlo Gavazzi UWP 3.0 Sentilo Proxy |
No comments yet