← Back to browse · API

CVE-2022-3229

Severity
CRITICAL
CVSS
9.8
EPSS
0.66354
Risk score
62.42
CISA KEV
No
PoC
No
Published
2023-02-06
Modified
2025-03-25
First seen
2026-08-07
Aliases
EUVD-2022-42640, GHSA-V2R7-FRXX-FMQ5
Products
Unified Intents AB:Unified Remote 0 ≤3.11.0.2483 (50)
Sources
euvd EUVD-2022-42640

Description

Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.

References