Unauthenticated Remote Password Reset Vulnerability in IFM Moneo Appliance

Unauthenticated Remote Password Reset Vulnerability in IFM Moneo Appliance

CVE-2022-3485 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.

Learn more about our Web Application Penetration Testing UK.