CVE-2022-28811: Gavazziautomation Cpy Car Park Server
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.
Affected products
- Gavazziautomation Cpy Car Park Server: before 2.8.3 (fixed in 2.8.3)
- Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller Firmware: before 8.5.0.3 (fixed in 8.5.0.3)
Published 2022-09-28. Last modified 2026-06-17.