CVE-2022-1300

CRITICAL

TRUMPF TruTops Boost 13.01-13.05 and TruTops Fab/Monitor 22.01-22.05 - Unauthenticated Critical Function Access

Title source: llm
STIX 2.1

Description

Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_confirm
https://cert.vde.com/en/advisories/VDE-2022-016/

Scores

CVSS v3 9.8
EPSS 0.0137
EPSS Percentile 68.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (6)
trumpf/trutops_boost 13.08.21
trumpf/trutops_boost 13.01 - 13.05
trumpf/trutops_fab 22.08.21
trumpf/trutops_fab 22.01 - 22.05
trumpf/trutops_monitor 22.08.21
trumpf/trutops_monitor 22.01 - 22.05
Published May 02, 2022
Tracked Since Feb 18, 2026