VYPR
Unrated severityNVD Advisory· Published Sep 28, 2022· Updated May 21, 2025

Carlo Gavazzi UWP 3.0 WebApp allows for authentication bypass

CVE-2022-22523

Description

An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authentication bypass in Carlo Gavazzi UWP 3.0 and CPY Car Park Server Web-App allows unauthorized access when free-access is disabled.

Vulnerability

An improper authentication vulnerability exists in the Carlo Gavazzi UWP 3.0 family of Monitoring Gateways and Controllers across multiple versions, and in the CPY Car Park Server Version 2.8.3 Web-App [1]. The flaw allows an attacker to bypass authentication mechanisms when the free-access feature is disabled, enabling unauthorized access to the web interface [1].

Exploitation

An attacker with network access to the affected device’s web interface can exploit this vulnerability without prior authentication. The exploitation requires that the free-access setting is disabled, which is a common security configuration. By manipulating authentication requests, the attacker can bypass the login process and gain access to the web application as an unauthorized user [1].

Impact

Successful exploitation grants the attacker access to the web interface of the device in the context of an unauthorized user. This can lead to further attacks, such as information disclosure, configuration changes, or denial of service, depending on the capabilities exposed through the web interface. The advisory describes the overall impact as allowing an attacker to get full access to the affected devices [1].

Mitigation

Carlo Gavazzi has released firmware updates for the UWP 3.0 family and a software update for the CPY Car Park Server to address this vulnerability. Users should update to the latest versions as specified in the advisory from the vendor. The advisory is published by CERT@VDE under reference VDE-2022-029 [1]. No workaround is mentioned if patching is not immediately possible, but disabling web access from untrusted networks reduces risk.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

6
  • = 2.8.3+ 1 more
    • (no CPE)range: = 2.8.3
    • (no CPE)range: 2
  • Carlo Gavazzi/UWP 3.0 Monitoring Gateway and Controllerv5
    Range: 8
  • Carlo Gavazzi/UWP 3.0 Monitoring Gateway and Controller – EDP versionv5
    Range: 8
  • Carlo Gavazzi/UWP 3.0 Monitoring Gateway and Controller – Security Enhancedv5
    Range: 8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.