VYPR

Vitogate 300

by Viessmann

CVEs (3)

  • CVE-2023-45852CriOct 14, 2023
    risk 0.65cvss 9.8epss 0.14

    In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

  • CVE-2023-5222MedSep 27, 2023
    risk 0.50cvss 6.3epss 0.75

    A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. The manipulation leads to use of hard-coded password. The…

  • CVE-2023-5702MedOct 23, 2023
    risk 0.32cvss 4.3epss 0.15

    A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used.…