{"api_version":"1","generated_at":"2026-07-23T13:49:54+00:00","cve":"CVE-2022-22525","urls":{"html":"https://cve.report/CVE-2022-22525","api":"https://cve.report/api/cve/CVE-2022-22525.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-22525","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-22525"},"summary":{"title":"CVE-2022-22525","description":"In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function","state":"PUBLIC","assigner":"info@cert.vde.com","published_at":"2022-09-28 14:15:00","updated_at":"2022-09-30 02:09:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://cert.vde.com/en/advisories/VDE-2022-029/","name":"https://cert.vde.com/en/advisories/VDE-2022-029/","refsource":"CONFIRM","tags":[],"title":"VDE-2022-029 | CERT@VDE","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-22525","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-22525","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Vera Mens from Claroty Research","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"22525","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gavazziautomation","cpe5":"cpy_car_park_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"22525","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"gavazziautomation","cpe5":"uwp_3.0_monitoring_gateway_and_controller","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"22525","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"gavazziautomation","cpe5":"uwp_3.0_monitoring_gateway_and_controller","cpe6":"-","cpe7":"*","cpe8":"edp","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"22525","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"gavazziautomation","cpe5":"uwp_3.0_monitoring_gateway_and_controller","cpe6":"-","cpe7":"*","cpe8":"security_enhanced","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"22525","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"gavazziautomation","cpe5":"uwp_3.0_monitoring_gateway_and_controller_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"22525","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"gavazziautomation","cpe5":"uwp_3.0_monitoring_gateway_and_controller_firmware","cpe6":"*","cpe7":"*","cpe8":"edp","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"22525","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"gavazziautomation","cpe5":"uwp_3.0_monitoring_gateway_and_controller_firmware","cpe6":"*","cpe7":"*","cpe8":"security_enhanced","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"info@cert.vde.com","ID":"CVE-2022-22525","STATE":"PUBLIC","TITLE":"Command injection in restore function of Carlo Gavazzi UWP3.0 allows for command injection"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"UWP 3.0 Monitoring Gateway and Controller","version":{"version_data":[{"version_affected":"<","version_name":"8","version_value":"8.5.0.3"}]}},{"product_name":"UWP 3.0 Monitoring Gateway and Controller – Security Enhanced","version":{"version_data":[{"version_affected":"<","version_name":"8","version_value":"8.5.0.3"}]}},{"product_name":"UWP 3.0 Monitoring Gateway and Controller – EDP version","version":{"version_data":[{"version_affected":"<","version_name":"8","version_value":"8.5.0.3"}]}},{"product_name":"CPY Car Park Server","version":{"version_data":[{"version_affected":"<","version_name":"2","version_value":"2.8.3"}]}}]},"vendor_name":"Carlo Gavazzi"}]}},"credit":[{"lang":"eng","value":"Vera Mens from Claroty Research"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function"}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20 Improper Input Validation"}]}]},"references":{"reference_data":[{"name":"https://cert.vde.com/en/advisories/VDE-2022-029/","refsource":"CONFIRM","url":"https://cert.vde.com/en/advisories/VDE-2022-029/"}]},"source":{"advisory":"VDE-2022-029","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-09-28 14:15:00","lastModifiedDate":"2022-09-30 02:09:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gavazziautomation:cpy_car_park_server:*:*:*:*:*:*:*:*","versionEndExcluding":"2.8.3","cpe_name":[]}]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"8.5.0.3","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:edp:*:*:*:*:*","versionEndExcluding":"8.5.0.3","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:edp:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:security_enhanced:*:*:*:*:*","versionEndExcluding":"8.5.0.3","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:security_enhanced:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"22525","Ordinal":"224866","Title":"CVE-2022-22525","CVE":"CVE-2022-22525","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"22525","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}