# CVE-2022-3485

## Summary

- **CVE ID:** CVE-2022-3485
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-640
- **Published:** Dec 12, 2022
- **Last Modified:** Mar 13, 2026

## Description

In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.

## Affected Products

- ifm — moneo appliance (0)

## References

- [CNA](https://cert.vde.com/en/advisories/VDE-2022-050/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.93%
- **EPSS Percentile:** 58.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._