ID

VAR-202206-1898


CVE

CVE-2022-33202


TITLE

L2Blocker Authentication evasion vulnerability in sensor setting screen

Trust: 0.8

sources: JVNDB: JVNDB-2022-000048

DESCRIPTION

Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by using alternative paths or channels for Sensor. Provided by Soft Create Co., Ltd. (CWE-288) Exists. This vulnerability information is based on the Information Security Early Warning Partnership. IPA Report to JPCERT/CC Coordinated with the developer. Reporter : Cyber Defense Institute Inc.A third party who can access the device may log in illegally, and the information in the device may be stolen or malfunction

Trust: 1.71

sources: NVD: CVE-2022-33202 // JVNDB: JVNDB-2022-000048 // VULMON: CVE-2022-33202

IOT TAXONOMY

category:['network device']sub_category:router

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:softcreatemodel:l2blockerscope:ltversion:4.8.6

Trust: 1.0

vendor:株式会社ソフトクリエイトmodel:l2blockerscope: - version: -

Trust: 0.8

vendor:株式会社ソフトクリエイトmodel:l2blockerscope:lteversion:on-premises ver4.8.5 and earlier s

Trust: 0.8

vendor:株式会社ソフトクリエイトmodel:l2blockerscope:eqversion: -

Trust: 0.8

vendor:株式会社ソフトクリエイトmodel:l2blockerscope:lteversion:cloud ver4.8.5 and earlier s

Trust: 0.8

sources: JVNDB: JVNDB-2022-000048 // NVD: CVE-2022-33202

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-33202
value: HIGH

Trust: 1.0

IPA: JVNDB-2022-000048
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202206-2536
value: HIGH

Trust: 0.6

VULMON: CVE-2022-33202
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2022-33202
severity: MEDIUM
baseScore: 4.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

IPA: JVNDB-2022-000048
severity: MEDIUM
baseScore: 4.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:N
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2022-33202
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 5.2
version: 3.1

Trust: 1.0

IPA: JVNDB-2022-000048
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2022-33202 // JVNDB: JVNDB-2022-000048 // CNNVD: CNNVD-202206-2536 // NVD: CVE-2022-33202

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.0

problemtype:Inappropriate authentication (CWE-287) [IPA evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-000048 // NVD: CVE-2022-33202

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202206-2536

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202206-2536

PATCH

title:L2Blocker Authentication evasion vulnerability in sensor setting screenurl:https://www.softcreate.co.jp/news/detail/210

Trust: 0.8

title:SOFTCREATE L2Blocker Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=199008

Trust: 0.6

sources: JVNDB: JVNDB-2022-000048 // CNNVD: CNNVD-202206-2536

EXTERNAL IDS

db:NVDid:CVE-2022-33202

Trust: 3.4

db:JVNid:JVN51464799

Trust: 2.5

db:JVNDBid:JVNDB-2022-000048

Trust: 1.4

db:CNNVDid:CNNVD-202206-2536

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2022-33202

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2022-33202 // JVNDB: JVNDB-2022-000048 // CNNVD: CNNVD-202206-2536 // NVD: CVE-2022-33202

REFERENCES

url:https://www.softcreate.co.jp/news/detail/210

Trust: 1.7

url:https://jvn.jp/en/jp/jvn51464799/index.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-33202

Trust: 1.4

url:https://jvn.jp/jp/jvn51464799/index.html

Trust: 0.8

url:https://jvndb.jvn.jp/en/contents/2022/jvndb-2022-000048.html

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-33202/

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2022-33202 // JVNDB: JVNDB-2022-000048 // CNNVD: CNNVD-202206-2536 // NVD: CVE-2022-33202

SOURCES

db:OTHERid: -
db:VULMONid:CVE-2022-33202
db:JVNDBid:JVNDB-2022-000048
db:CNNVDid:CNNVD-202206-2536
db:NVDid:CVE-2022-33202

LAST UPDATE DATE

2025-01-30T19:32:03.347000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2022-33202date:2022-07-07T00:00:00
db:JVNDBid:JVNDB-2022-000048date:2024-06-18T01:41:00
db:CNNVDid:CNNVD-202206-2536date:2022-07-08T00:00:00
db:NVDid:CVE-2022-33202date:2022-07-07T14:07:06.300

SOURCES RELEASE DATE

db:VULMONid:CVE-2022-33202date:2022-06-27T00:00:00
db:JVNDBid:JVNDB-2022-000048date:2022-06-24T00:00:00
db:CNNVDid:CNNVD-202206-2536date:2022-06-24T00:00:00
db:NVDid:CVE-2022-33202date:2022-06-27T01:15:07.340