We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-22806



Description

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=1031: UPS 03.1 and prior)

Reserved 2022-01-07 | Published 2022-03-09 | Updated 2024-08-03 | Assigner schneider

Problem types

CWE-294 Authentication Bypass by Capture-replay

Product status

SMT Series
affected

SMC Series
affected

SMTL Series
affected

SCL Series
affected

SMX Series
affected

References

www.se.com/ww/en/download/document/SEVD-2022-067-02/

cve.org (CVE-2022-22806)

nvd.nist.gov (CVE-2022-22806)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2022-22806

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.