CVE-2022-3485
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.80%
- CWE
- CWE-640
- Published
- 2022-12-12
- Last modified
- 2026-03-13
Affected products
- ifm moneo appliance
Weakness type
Related vulnerabilities
- CVE-2023-7028 — Weak Password Recovery Mechanism for Forgotten Password in GitLab
- CVE-2025-6216 — Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability
- CVE-2025-47646 — WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
- CVE-2026-18963 — Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2024-8878 — Unauthenticated Password Reset
- CVE-2023-30466 — Authentication Bypass Vulnerability in Milesight Network Video Recorder (NVR)
- CVE-2024-11350 — AdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account Takeover
- CVE-2022-50910 — Beehive Forum - Account Takeover