SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-2052

An adversary may use these accounts to remotely gain full access to the system.

CRITICAL 9.8EPSS 0.66%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.66% probability · 50th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
trumpf/job order interface · trumpf/oseon · trumpf/trutops boost · trumpf/trutops fab · trumpf/trutops monitor
Source
info@cert.vde.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.