VendorsGavazzi Automationuwp_3.0_monitoring_gateway_and_controller_firmwareall versions
Vulnerabilities

Gavazzi Automation Uwp 3.0 Monitoring Gateway And Controller Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-28814
Path traversal in Carlo Gavazzi UWP 3.0 could lead to full device access
Published 2022-09-28 · Modified
9.8EPSS 0.013
CVE-2022-28811
Possible command injection in Car Park Server in Carlo Gavazzi UWP3.0
Published 2022-09-28 · Modified
9.8EPSS 0.012
CVE-2022-22522
Hard-coded credentials in Carlo Gavazzi UWP3.0 allows for authentication bypass and full control of the device
Published 2022-09-28 · Modified
9.8EPSS 0.011
CVE-2022-28812
Use of Hard-coded Credentials in UWP3.0 allows SuperUser authentication bypass in Car Park Server.
Published 2022-09-28 · Modified
9.8EPSS 0.010
CVE-2022-22526
Missing authentication for API in Carlo Gavazzi UWP 3.0 Car Park Server
Published 2022-09-28 · Modified
9.8EPSS 0.008
CVE-2022-22524
SQL-injection in Carlo Gavazzi UWP 3.0 allows for full database access
Published 2022-09-28 · Modified
9.4EPSS 0.012
CVE-2022-28813
SQL-injection in Car Park Server 3.0 allows for full database access.
Published 2022-09-28 · Modified
7.5EPSS 0.010
CVE-2022-22523
Carlo Gavazzi UWP 3.0 WebApp allows for authentication bypass
Published 2022-09-28 · Modified
7.5EPSS 0.009
CVE-2022-22525
Command injection in restore function of Carlo Gavazzi UWP3.0 allows for command injection
Published 2022-09-28 · Modified
7.2EPSS 0.012
CVE-2022-28816
Reflected XSS in Carlo Gavazzi UWP 3.0
Published 2022-09-28 · Modified
6.1EPSS 0.004
CVE-2022-28815
SQL-Injection in Carlo Gavazzi UWP 3.0 Sentilo Proxy
Published 2022-09-28 · Modified
2.7EPSS 0.005