VendorsViessmannvitogate_300_firmwareall versions
Vulnerabilities

Viessmann Vitogate 300 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-5222
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
Published 2023-09-27 · Modified
9.81 PoCEPSS 0.745
CVE-2023-45852
In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.
Published 2023-10-14 · Modified
9.8EPSS 0.140
CVE-2023-5702
Viessmann Vitogate 300 direct request
Published 2023-10-23 · Modified
6.51 PoCEPSS 0.145