CVE-2022-3485

CRITICAL

IFM Moneo Qha210 Firmware < 1.9.3 - Password Reset Weakness

Title source: rule

Description

In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.

Scores

CVSS v3 9.8
EPSS 0.0080
EPSS Percentile 73.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-640
Status published

Affected Products (2)

ifm/moneo_qha210_firmware < 1.9.3
ifm/moneo_qha200_firmware < 1.9.3

Timeline

Published Dec 12, 2022
Tracked Since Feb 18, 2026