Carlo Gavazzi UWP 3.0 WebApp allows for authentication bypass
Description
An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An authentication bypass in Carlo Gavazzi UWP 3.0 and CPY Car Park Server Web-App allows unauthorized access when free-access is disabled.
Vulnerability
An improper authentication vulnerability exists in the Carlo Gavazzi UWP 3.0 family of Monitoring Gateways and Controllers across multiple versions, and in the CPY Car Park Server Version 2.8.3 Web-App [1]. The flaw allows an attacker to bypass authentication mechanisms when the free-access feature is disabled, enabling unauthorized access to the web interface [1].
Exploitation
An attacker with network access to the affected device’s web interface can exploit this vulnerability without prior authentication. The exploitation requires that the free-access setting is disabled, which is a common security configuration. By manipulating authentication requests, the attacker can bypass the login process and gain access to the web application as an unauthorized user [1].
Impact
Successful exploitation grants the attacker access to the web interface of the device in the context of an unauthorized user. This can lead to further attacks, such as information disclosure, configuration changes, or denial of service, depending on the capabilities exposed through the web interface. The advisory describes the overall impact as allowing an attacker to get full access to the affected devices [1].
Mitigation
Carlo Gavazzi has released firmware updates for the UWP 3.0 family and a software update for the CPY Car Park Server to address this vulnerability. Users should update to the latest versions as specified in the advisory from the vendor. The advisory is published by CERT@VDE under reference VDE-2022-029 [1]. No workaround is mentioned if patching is not immediately possible, but disabling web access from untrusted networks reduces risk.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
6= 2.8.3+ 1 more
- (no CPE)range: = 2.8.3
- (no CPE)range: 2
- Carlo Gavazzi/UWP 3.0 Monitoring Gateway and Controllerv5Range: 8
- Carlo Gavazzi/UWP 3.0 Monitoring Gateway and Controller – EDP versionv5Range: 8
- Carlo Gavazzi/UWP 3.0 Monitoring Gateway and Controller – Security Enhancedv5Range: 8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- cert.vde.com/en/advisories/VDE-2022-029/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.