CVE-2022-42787 - CVE House
Back to Database
Status published High CVE-2022-42787

Wiesemann & Theis: Small number space for allocating session id in Com-Server family

Vulnerability Description

Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user interaction is required.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-42787

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Wiesemann & Theis

View all reports →

Affected Software

Com-Server LC, Com-Server PoE 3 x Isolated, Com-Server 20mA, Com-Server ++, AT-Modem-Emulator, Com-Server UL, Com-Server Highspeed 100BaseFX, Com-Server Highspeed 100BaseLX, Com-Server Highspeed Office 1 Port, Com-Server Highspeed Office 4 Port, Com-Server Highspeed Industry, Com-Server Highspeed OEM, Com-Server Highspeed Compact, Com-Server Highspeed Isolated, Com-Server Highspeed 19" 1Port, Com-Server Highspeed 19" 4Port, Com-Server Highspeed PoE
Vulnerable Versions:
1.0

Timeline

Official Publish: November 10th, 2022
Last Modified: May 1st, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.