CMC III
by Rittal
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40222 | Hig | 0.47 | 7.2 | 0.05 | Sep 9, 2021 | Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is possible to introduce shell code to create a reverse shell in the PU-Hostname field of the TCP/IP Configuration dialog. Web… | ||
| CVE-2019-19393 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2020 | The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other… | ||
| CVE-2022-40633 | Med | 0.30 | 4.6 | 0.00 | Mar 2, 2023 | A malicious actor can clone access cards used to open control cabinets secured with Rittal CMC III locks. |
- risk 0.47cvss 7.2epss 0.05
Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is possible to introduce shell code to create a reverse shell in the PU-Hostname field of the TCP/IP Configuration dialog. Web…
- risk 0.40cvss 6.1epss 0.01
The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other…
- risk 0.30cvss 4.6epss 0.00
A malicious actor can clone access cards used to open control cabinets secured with Rittal CMC III locks.