CVE-2022-1525
The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-602: Client-Side Enforcement of Server-Side Security, which could allow attackers to bypass web access controls by inspecting and modifying the source code of password protected web elements.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-602
- Published
- 2022-09-06
- Last modified
- 2026-03-13
Affected products
- Cognex 3D-A1000 Dimensioning System
Weakness type
Related vulnerabilities
- CVE-2026-23478 — Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
- CVE-2025-33025 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-33024 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-32469 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2020-24683 — Authentication Bypass in Symphony Plus
- CVE-2023-0750 — Yellowbrik PEC-1864 authentication bypass
- CVE-2022-20658 — Cisco Unified Contact Center Management Portal and Unified Contact Center Domain Manager Privilege Escalation Vulnerability
- CVE-2026-25737 — Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)