CVE-2022-2052

CRITICAL

Trumpf Job Order Interface OSEON and TruTops Products - Unauthenticated Remote Access via Default Privileged Accounts

Title source: llm
STIX 2.1

Description

Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0062
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (5)
trumpf/job_order_interface
trumpf/oseon < 1.6
trumpf/trutops_boost
trumpf/trutops_fab
trumpf/trutops_monitor
Published Oct 17, 2022
Tracked Since Feb 18, 2026