CVE-2022-2052 CRITICAL

CVE-2022-2052: TRUMPF TruTops default user accounts vulnerability

Vendor Trumpf Werkzeugmaschinen Se + Co. Kg
Product TruTops Monitor
Weakness CWE-284
Published October 17, 2022
Last update May 10, 2025

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

Key dates

02Disclosure timeline

October 17, 2022 CVE published
May 10, 2025 Record updated