CVE-2022-3010
Last modified
CVE-2022-3010 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite.. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Priva | Top Control Suite | <= 8.7.8.0 |
References
- https://csirt.divd.nl/CVE-2022-3010Broken Link
- https://csirt.divd.nl/DIVD-2022-00035Broken Link
- https://www.cisa.gov/news-events/ics-advisories/icsa-22-356-01Third Party Advisory, US Government Resource
- https://csirt.divd.nl/CVE-2022-3010Broken Link
- https://csirt.divd.nl/DIVD-2022-00035Broken Link
- https://www.cisa.gov/news-events/ics-advisories/icsa-22-356-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3010?
How severe is CVE-2022-3010?
How do I fix CVE-2022-3010?
Are you affected by CVE-2022-3010?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
