{"api_version":"1","generated_at":"2026-07-23T10:03:46+00:00","cve":"CVE-2022-4780","urls":{"html":"https://cve.report/CVE-2022-4780","api":"https://cve.report/api/cve/CVE-2022-4780.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-4780","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-4780"},"summary":{"title":"CVE-2022-4780","description":"ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change.","state":"PUBLIC","assigner":"vulnerability@ncsc.ch","published_at":"2022-12-29 00:15:00","updated_at":"2023-11-07 03:58:00"},"problem_types":["CWE-798"],"metrics":[],"references":[{"url":"https://elvexys.com/products/xpg-gateway-rtu-protocol-converter/isos-release-notes/","name":"https://elvexys.com/products/xpg-gateway-rtu-protocol-converter/isos-release-notes/","refsource":"MISC","tags":[],"title":"ISOS release notes - Elvexys SA","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-4780","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4780","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"4780","vulnerable":"1","versionEndIncluding":"2.00","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"elvexys","cpe5":"isos_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2022-4780","ASSIGNER":"vulnerability@ncsc.ch","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"elvexys","product":{"product_data":[{"product_name":"ISOS","version":{"version_data":[{"version_value":"1.81","version_affected":"="}]}}]}}]}},"references":{"reference_data":[{"url":"https://elvexys.com/products/xpg-gateway-rtu-protocol-converter/isos-release-notes/","refsource":"MISC","name":"https://elvexys.com/products/xpg-gateway-rtu-protocol-converter/isos-release-notes/"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"EXTERNAL"},"solution":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"ISOS firmwares from version 2.01 force the user to change the default credentials during the first login.<br>For\n ISOS fimwares up to version 2.00, the default credentials must be \nchanged by the user as documented in the « Initial staging » and « User \naccess » chapters. "}],"value":"ISOS firmwares from version 2.01 force the user to change the default credentials during the first login.\nFor\n ISOS fimwares up to version 2.00, the default credentials must be \nchanged by the user as documented in the « Initial staging » and « User \naccess » chapters. "}],"credits":[{"lang":"en","value":"Damian Pfammatter, Cyber-Defense Campus, armasuisse S+T"},{"lang":"en","value":"Daniel Hulliger, Cyber-Defense Campus, armasuisse S+T"}],"impact":{"cvss":[{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":4.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.1"}]}},"nvd":{"publishedDate":"2022-12-29 00:15:00","lastModifiedDate":"2023-11-07 03:58:00","problem_types":["CWE-798"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:elvexys:isos_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"1.81","versionEndIncluding":"2.00","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}