Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
CVE-2023-5222
What is CVE-2023-5222?
A significant security flaw exists in the Viessmann Vitogate 300's Web Management Interface. This issue lies within the function isValidUser found in the /cgi-bin/vitogate.cgi file. An attacker can potentially exploit this vulnerability by utilizing a hard-coded password, thus bypassing authentication procedures. Given that this vulnerability has been publicly disclosed, it presents a serious risk to users of affected versions, especially since the vendor did not respond to notifications regarding this security concern.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Vitogate 300 2.1.0
Vitogate 300 2.1.1
Vitogate 300 2.1.2
References
EPSS Score
89% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
