CVE Database
/

CVE-2022-42787

Back to search

CVE-2022-42787

Published: Nov 10, 2022

Modified: May 1, 2025

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user interaction is required.

VendorProductVersions

Wiesemann & Theis

Com-Server LC

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server PoE 3 x Isolated

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server 20mA

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server ++

affected
1.0 - < 1.48

Wiesemann & Theis

AT-Modem-Emulator

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server UL

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server Highspeed 100BaseFX

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed 100BaseLX

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Office 1 Port

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Office 4 Port

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Industry

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed OEM

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Compact

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Isolated

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed 19" 1Port

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed 19" 4Port

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed PoE

affected
1.0 - < 1.76

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now