CVE-2022-47558

CRITICAL

Ormazabal ekorRCI and ekorCCP Firmware - Unauthenticated FTP Access via Default Credentials

Title source: llm
STIX 2.1

Description

Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or modify existing users, modify configuration files, install rootkits or backdoors.

Scores

CVSS v3 9.4
EPSS 0.0052
EPSS Percentile 39.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284 CWE-798
Status published
Products (2)
ormazabal/ekorccp_firmware 601j
ormazabal/ekorrci_firmware 601j
Published Sep 19, 2023
Tracked Since Feb 18, 2026