High severity8.8NVD Advisory· Published Nov 10, 2022· Updated Jun 17, 2026
CVE-2022-42787
CVE-2022-42787
Description
Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user interaction is required.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 1.0
1.0+ 1 more
- (no CPE)range: 1.0
- (no CPE)range: 1.0
Patches
Vulnerability mechanics
References
1- cert.vde.com/de/advisories/VDE-2022-043nvdVendor Advisory
News mentions
0No linked articles in our index yet.