Description
The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to execute malicious actions when a user is logged in.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Ormazabal recommends upgrading to updated models.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-50320 | The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to execute malicious actions when a user is logged in. |
References
History
Wed, 18 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-18T14:27:40.985Z
Reserved: 2022-12-19T16:35:50.462Z
Link: CVE-2022-47560
Updated: 2024-08-03T14:55:08.286Z
Status : Modified
Published: 2023-09-20T08:15:10.787
Modified: 2024-11-21T07:32:11.777
Link: CVE-2022-47560
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD