CVE-2022-25594

MEDIUM

Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote attacker can input specific URLs to acquire partial system configuration information.

Affects 1 product across 1 vendor.

BCS4.28
CVSS 3.15.3
EPSS1.0%
Percentile59th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-200: Exposure of Sensitive Information

Application reveals restricted data such as system internals, credentials, or user data to unauthorized actors.

Related Attack Patterns (CAPEC)
CAPEC-13 Subverting Environment Variable Values
via CWE-200
CAPEC-59 Session Credential Falsification through Prediction
via CWE-200
CAPEC-60 Reusing Session IDs (aka Session Replay)
via CWE-200
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-200
CAPEC-285 ICMP Echo Request Ping
via CWE-200
Show all 59

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Microprogram's parking lot management system is vulnerable to sensitive information exposure, allowing unauthorized remote attackers to access partial system configuration information through specific URL inputs.

BSID: BS-2022-GLOBAL-069420-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-25594?
Microprogram's parking lot management system is vulnerable to sensitive information exposure, allowing unauthorized remote attackers to access partial system configuration information through specific URL inputs.
What is the CVSS score for CVE-2022-25594?
CVE-2022-25594 has CVSS 5.3 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. EPSS: 1.0%.
Is CVE-2022-25594 actively exploited?
No confirmed active exploitation of CVE-2022-25594 as of 2026-05-30.
How do I remediate CVE-2022-25594?
Priority: MEDIUM.
What systems are affected by CVE-2022-25594?
CVE-2022-25594 affects: Program.
Vulnerability Details
CVE IDCVE-2022-25594
BSIDBS-2022-GLOBAL-069420-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published2022-04-07
Last Modified2024-11-21
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote attacker can input specific URLs to acquire partial system configuration information.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by sending crafted HTTP requests to the system's web interface, which may result in the disclosure of sensitive configuration details.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Program Parking Lot Management System
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1570 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashc1bb16da0c848c8ca4fb9a4d35485fc9ae3c3e6960f487053acd01b925ce597f331b31c11b114d69601da05652a6d111b8dd21562bf334931cc91817eae6362f
Related CVEs affecting Program
CVE-1999-0565 10.0 A Sendmail alias allows input to be piped to a program. CVE-2025-25174 10.0 Improper Control of Filename for Include/Require Statement in PHP Program ('P... CVE-2024-49314 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in jiangqie Jia... CVE-1999-0663 10.0 A system-critical program, library, or file has a checksum or other integrity... CVE-1999-0662 10.0 A system-critical program or library does not have the appropriate patch, hot...
View all Program CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →