9.8
CVSSv3

CVE-2022-22831

Published: 06/02/2022 Updated: 11/02/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

servisnet tessa 0.0.2

Exploits

This Metasploit module exploits an authentication bypass in Servisnet Tessa, triggered by add new sysadmin user The appjs is publicly available which acts as the backend of the application By exposing a default value for the "Authorization" HTTP header, it is possible to make unauthenticated requests to some areas of the application Even MQTT ( ...