First published: Fri Mar 31 2023(Updated: )
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of the device, allowing him to replace the administrator password.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Generex Cs141 Firmware | <2.06 | |
Generex CS141 |
This vulnerability has been fixed by Generex team in CS141 version 2.12, released on December 2022.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47192 is a vulnerability in Generex UPS CS141 below version 2.06 that allows a remote attacker to upload a modified backup file and replace the administrator password.
CVE-2022-47192 affects Generex UPS CS141 devices below version 2.06 by allowing a remote attacker to upload a backup file containing a modified "users.json" file and replace the administrator password.
CVE-2022-47192 has a severity rating of 8.8 (high).
To fix CVE-2022-47192, you should update your Generex UPS CS141 device to version 2.06 or higher.
You can find more information about CVE-2022-47192 at the following references: [Link 1](https://www.generex.de/support/changelogs/cs141/2-12), [Link 2](https://www.generex.de/support/changelogs/cs141/page:2), [Link 3](https://www.incibe-cert.es/en/early-warning/ics-advisories/update-03032023-multiple-vulnerabilities-generex-ups-cs141)