CVE-2022-47767
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included). This does not exist in SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.25% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-912
- Affected
- solar-log/solar-log 250 firmware · solar-log/solar-log 300 firmware · solar-log/solar-log 500 firmware · solar-log/solar-log 800e firmware · solar-log/solar-log 1000 firmware · solar-log/solar-log 1000 pm\+ firmware · solar-log/solar-log 1200 firmware · solar-log/solar-log 2000 firmware · solar-log/solar-log 50 firmware
- Source
- cve@mitre.org
References
- https://www.solar-log.com/en/support/firmware-database-1Vendor Advisory
- https://www.swascan.com/security-advisory-solar-log/Exploit, Third Party Advisory
- https://www.solar-log.com/en/support/firmware-database-1Vendor Advisory
- https://www.swascan.com/security-advisory-solar-log/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.