Vulnerability CVE-2022-2105


Published: 2022-06-24

Description:
Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a ??root? user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.

Type:

CWE-841

(Improper Enforcement of Behavioral Workflow)

 References:
https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03

Copyright 2026, cxsecurity.com

 

Back to Top