← Back to browse · API

CVE-2023-5222

Severity
MEDIUM
CVSS
6.3
EPSS
0.74525
Risk score
51.28
CISA KEV
No
PoC
No
Published
2023-09-27
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-57551, GHSA-CM4F-G738-HP2G
Products
Viessmann:Vitogate 300 2.1.0, Viessmann:Vitogate 300 2.1.1, Viessmann:Vitogate 300 2.1.2, Viessmann:Vitogate 300 2.1.3
Sources
euvd EUVD-2023-57551

Description

A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240364. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References