CVE-2023-5222
A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240364. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 89.71%
- CWE
- CWE-259
- Published
- 2023-09-27
- Last modified
- 2026-03-13
Affected products
- Viessmann Vitogate 300
- Viessmann Vitogate 300
- Viessmann Vitogate 300
- Viessmann Vitogate 300
Weakness type
Related vulnerabilities
- CVE-2024-7332 — TOTOLINK CP450 Telnet Service product.ini hard-coded password
- CVE-2012-5862 — Sinapsi eSolar Hard-Coded Password
- CVE-2023-2645 — USR USR-G806 Web Management Page hard-coded password
- CVE-2022-45444 — CVE-2022-45444
- CVE-2014-2363 — Morpho Itemiser 3 Hard-Coded Credential
- CVE-2025-8730 — Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
- CVE-2025-11126 — Apeman ID71 system.ini hard-coded credentials
- CVE-2024-32741 — A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded pa