CVE-2022-10652
A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15.
v2021 versions prior to R4 of 2022-01-15.
v2020 versions prior to R6 of 2022-01-15.
v2019 versions later than R5 (service pack)
v2018 versions later than R5 (service pack). This issue does not affect: Abacus ERP v2019 versions prior to R5 of 2020-03-15.
v2018 versions prior to R7 of 2020-04-15.
v2017 version and prior versions and prior versions.
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Exploitation evidence
1 of 7 sourcesExploitation momentum
422 days of EPSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N- 19 Apr 2022Published to NVD
- 17 Jun 2026Last modified
Public Exploits & PoCs
2ATT&CK techniques
1Techniques this CVE enables. Pills with a solid outline are high confidence - named directly in ATT&CK or Nuclei, or human-curated by CTID; the rest are inferred from the weakness type using MITRE's CVE Mapping Methodology and the CWE → CAPEC chain. Broad, generic-weakness guesses are filtered out. A small N× marks a technique that N independent sources agree on.
▤ Build a SIEM detection for these techniquesCAPEC attack patterns
10Attack patterns this CVE enables - the bridge from weakness to ATT&CK technique.