7.5
CVSSv3

CVE-2022-22833

Published: 06/02/2022 Updated: 10/02/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

servisnet tessa 0.0.2

Exploits

This Metasploit module exploits an MQTT credential disclosure vulnerability in Servisnet Tessa The appjs is publicly available which acts as the backend of the application By exposing a default value for the "Authorization" HTTP header, it is possible to make unauthenticated requests to some areas of the application Even MQTT (Message Queuing T ...