CVE-2022-2302
Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowledge of the password.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.68%
- CWE
- CWE-304
- Published
- 2022-07-11
- Last modified
- 2026-03-13
Affected products
- LENZE cabinet c520
- LENZE cabinet c550
- LENZE cabinet c750
Weakness type
Related vulnerabilities
- CVE-2024-8954 — Authentication Bypass in composiohq/composio
- CVE-2022-2821 — Missing Critical Step in Authentication in namelessmc/nameless
- CVE-2024-45764 — Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. A
- CVE-2024-12048 — IDOR Vulnerability in transformeroptimus/superagi
- CVE-2019-16766 — 2FA bypass in Wagtail through new device path
- CVE-2026-55957 — Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
- CVE-2024-2172 — Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
- CVE-2022-1065 — Multi Factor Authentication Bypass in various versions of Abacus ERP