CVE-2022-45778

https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of the firewall with super administrator privileges through a configuration error in report.m.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hillstonenet:sc-6000-wv02_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hillstonenet:sc-6000-wv02:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hillstonenet:sc-6000-wv04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hillstonenet:sc-6000-wv04:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hillstonenet:sc-6000-wv08_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hillstonenet:sc-6000-wv08:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hillstonenet:sc-6000-wv12_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hillstonenet:sc-6000-wv12:-:*:*:*:*:*:*:*

History

14 Apr 2025, 13:15

Type Values Removed Values Added
CWE CWE-284

21 Nov 2024, 07:29

Type Values Removed Values Added
Summary
  • (es) https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 &lt;= 5.0.4.0 es vulnerable a un control de acceso incorrecto. Existe una vulnerabilidad de omisión de permisos en el firewall de la aplicación WEB de Hillstone. Un atacante puede ingresar al fondo del firewall con privilegios de superadministrador a través de un error de configuración en report.m.
References () https://gist.github.com/yinfei6/6ffff06db3f7d4c24de2f784c0db10df - Third Party Advisory () https://gist.github.com/yinfei6/6ffff06db3f7d4c24de2f784c0db10df - Third Party Advisory

Information

Published : 2022-12-27 22:15

Updated : 2025-04-14 13:15


NVD link : CVE-2022-45778

Mitre link : CVE-2022-45778

CVE.ORG link : CVE-2022-45778


JSON object : View

Products Affected

hillstonenet

  • sc-6000-wv08_firmware
  • sc-6000-wv02_firmware
  • sc-6000-wv04
  • sc-6000-wv12_firmware
  • sc-6000-wv12
  • sc-6000-wv02
  • sc-6000-wv08
  • sc-6000-wv04_firmware
CWE
NVD-CWE-Other CWE-284

Improper Access Control