ID:8387 - Exploit for Missing Authentication for Critical Function in Unified Remote Server - CVE-2022-3229
Published: September 22, 2022
Unified Remote Server
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authentication for the "/web/#/settings/security" endpoint available by default on port 9510/TCP. A remote non-authenticated attacker can access the application settings remotely to disable authentication and gain unauthorized access to the system.